CRITICAL🇵🇱 Wersja polska

CVE-2017-14100

CVSS 9.8v3.0pub. 2017-09-02upd. 2026-05-13

In Asterisk 11.x before 11.25.2, 13.x before 13.17.1, and 14.x before 14.6.1 and Certified Asterisk 11.x before 11.6-cert17 and 13.x before 13.13-cert5, unauthorized command execution is possible. The app_minivm module has an "externnotify" program configuration option that is executed by the MinivmNotify dialplan application. The application uses the caller-id name and number as part of a built string passed to the OS shell for interpretation and execution. Since the caller-id name and number can come from an untrusted source, a crafted caller-id name or number allows an arbitrary shell command injection.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Digium Asterisk

    APP
    Digium
    11.0.011.0.111.0.211.1.011.10.011.10.111.10.211.1.111.11.011.1.211.12.011.12.111.13.011.13.111.14.0+ 85 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-26499CRITICAL9.1PL ✓same product

SSRF w Asterisk przez nagłówek Identity w mechanizmie STIR/SHAKEN

CVE-2022-26651CRITICAL9.8PL ✓same product

SQL Injection w module func_odbc systemu Asterisk (AST-2022-003)

CVE-2023-37457HIGH7.5same product

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk versions 18.20.0 and pri...

CVE-2023-49786HIGH7.5same product

Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20....

CVE-2022-26498HIGH7.5same product

An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to download files tha...