CVE-2023-26567

HIGHCVSS 8.1/10EPSS 0.65%

Last modified

CVE-2023-26567 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. EPSS estimates a 0.65% chance of exploitation in the next 30 days.

Description

Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
0.65%

46.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SangomaFreepbx Linux 71805
SangomaFreepbx Linux 71904
SangomaFreepbx Linux 71910
SangomaFreepbx Linux 72002
SangomaFreepbx Linux 72008
SangomaFreepbx Linux 72011
SangomaFreepbx Linux 72104
SangomaFreepbx Linux 72105
SangomaFreepbx Linux 72109
SangomaFreepbx Linux 72112
SangomaFreepbx Linux 72201
SangomaFreepbx Linux 72202
SangomaFreepbx Linux 72203
SangomaFreepbx Linux 72302

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-26567?
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
How severe is CVE-2023-26567?
CVE-2023-26567 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 0.65% probability of exploitation in the next 30 days.
How do I fix CVE-2023-26567?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-26567?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST