Multiple Asterisk Products Access Control List Security Bypass Vulnerability
BID:71218
Info
Multiple Asterisk Products Access Control List Security Bypass Vulnerability
| Bugtraq ID: | 71218 |
| Class: | Access Validation Error |
| CVE: |
CVE-2014-8412 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 20 2014 12:00AM |
| Updated: | Jan 06 2015 01:02AM |
| Credit: | Andreas Steinmetz |
| Vulnerable: |
Gentoo Linux Asterisk Asterisk Open Source 1.8.3.1 |
| Not Vulnerable: | |
Discussion
Multiple Asterisk Products Access Control List Security Bypass Vulnerability
Multiple Asterisk products are prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow attackers to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
The following products are vulnerable:
Asterisk Open Source
Asterisk Certified Asterisk
Multiple Asterisk products are prone to a security-bypass vulnerability.
Successfully exploiting this issue will allow attackers to bypass security restrictions and perform unauthorized actions; this may aid in launching further attacks.
The following products are vulnerable:
Asterisk Open Source
Asterisk Certified Asterisk
Exploit / POC
Multiple Asterisk Products Access Control List Security Bypass Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Multiple Asterisk Products Access Control List Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Multiple Asterisk Products Access Control List Security Bypass Vulnerability
References:
References:
- Asterisk Homepage (Asterisk)