CVE-2012-2414
Summary
| CVE | CVE-2012-2414 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-04-30 20:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Asterisk | Open Source | 1.6.2.0 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc4 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc5 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc6 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc7 | All | All |
| Application | Asterisk | Open Source | 1.6.2.0 | rc8 | All | All |
| Application | Asterisk | Open Source | 1.6.2.1 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.1 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.10 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.10 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.10 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.11 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.11 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.11 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.12 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.12 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.13 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.14 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.14 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.15 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.15 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.15.1 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.16 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.16 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.16.1 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.16.2 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.17 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.17 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.17 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.17 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.6.2.17.1 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.17.2 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.17.3 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.18 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.18 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.18.1 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.18.2 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.19 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.19 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.2 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.20 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.21 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.22 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.23 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.3 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.4 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.5 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.6 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.6 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.6 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.7 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.7 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.7 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.7 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.6.2.8 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.8 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.9 | All | All | All |
| Application | Asterisk | Open Source | 1.6.2.9 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.6.2.9 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.6.2.9 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.0 | beta1 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | beta2 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | beta3 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | beta4 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | beta5 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | rc4 | All | All |
| Application | Asterisk | Open Source | 1.8.0 | rc5 | All | All |
| Application | Asterisk | Open Source | 1.8.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.1 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.1.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.1.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.10.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.10.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.10.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.10.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.10.0 | rc4 | All | All |
| Application | Asterisk | Open Source | 1.8.10.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.11.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.11.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.2 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.2.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.2.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.2.3 | All | All | All |
| Application | Asterisk | Open Source | 1.8.2.4 | All | All | All |
| Application | Asterisk | Open Source | 1.8.3 | All | All | All |
| Application | Asterisk | Open Source | 1.8.3 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.3 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.3 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.3.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.3.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.3.3 | All | All | All |
| Application | Asterisk | Open Source | 1.8.4 | All | All | All |
| Application | Asterisk | Open Source | 1.8.4 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.4 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.4 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.4.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.4.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.4.3 | All | All | All |
| Application | Asterisk | Open Source | 1.8.4.4 | All | All | All |
| Application | Asterisk | Open Source | 1.8.5 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.5.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.6.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.6.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.6.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.6.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.7.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.7.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.7.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.7.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.7.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | rc4 | All | All |
| Application | Asterisk | Open Source | 1.8.8.0 | rc5 | All | All |
| Application | Asterisk | Open Source | 1.8.8.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.8.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.9.0 | All | All | All |
| Application | Asterisk | Open Source | 1.8.9.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 1.8.9.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 1.8.9.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 1.8.9.1 | All | All | All |
| Application | Asterisk | Open Source | 1.8.9.2 | All | All | All |
| Application | Asterisk | Open Source | 1.8.9.3 | All | All | All |
| Application | Asterisk | Open Source | 10.0.0 | All | All | All |
| Application | Asterisk | Open Source | 10.0.0 | beta1 | All | All |
| Application | Asterisk | Open Source | 10.0.0 | beta2 | All | All |
| Application | Asterisk | Open Source | 10.0.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 10.0.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 10.0.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 10.0.1 | All | All | All |
| Application | Asterisk | Open Source | 10.1.0 | All | All | All |
| Application | Asterisk | Open Source | 10.1.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 10.1.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 10.1.1 | All | All | All |
| Application | Asterisk | Open Source | 10.1.2 | All | All | All |
| Application | Asterisk | Open Source | 10.1.3 | All | All | All |
| Application | Asterisk | Open Source | 10.2.0 | All | All | All |
| Application | Asterisk | Open Source | 10.2.0 | rc1 | All | All |
| Application | Asterisk | Open Source | 10.2.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 10.2.0 | rc3 | All | All |
| Application | Asterisk | Open Source | 10.2.0 | rc4 | All | All |
| Application | Asterisk | Open Source | 10.2.1 | All | All | All |
| Application | Asterisk | Open Source | 10.3.0 | All | All | All |
| Application | Asterisk | Open Source | 10.3.0 | rc2 | All | All |
| Application | Asterisk | Open Source | 10.3.0 | rc3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA48891 - Asterisk Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Debian -- Security Information -- DSA-2460-1 asterisk | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| osvdb.org/81454 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Asterisk Shell Command Execution Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| AST-2012-004 | af854a3a-2127-422b-91ae-364da2661108 | downloads.asterisk.org | Patch, Vendor Advisory |
| [SECURITY] Fedora 15 Update: asterisk-1.8.11.1-1.fc15 | af854a3a-2127-422b-91ae-364da2661108 | lists.fedoraproject.org | |
| Asterisk Manager Interface Lets Remote Authenticated Users Execute Shell Commands - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.