CVE-2023-26567
Summary
| CVE | CVE-2023-26567 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-26 20:15:00 UTC |
| Updated | 2023-05-05 15:10:00 UTC |
| Description | Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call. |
Risk And Classification
Problem Types: CWE-522
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sangoma | Freepbx Linux 7 | 1805 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 1904 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 1910 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2002 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2008 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2011 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2104 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2105 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2109 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2112 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2201 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2202 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2203 | All | All | All |
| Application | Sangoma | Freepbx Linux 7 | 2302 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Open Source - Sangoma Technologies | MISC | www.sangoma.com | |
| FreePBX | Open source, web-based, IP PBX management tool. | MISC | www.freepbx.org | |
| QSecure - Sangoma FreePBX Linux Insecure Permissions | MISC | qsecure.com.cy | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.