Vulnerability index

Browse CVEs

55 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Freepbx HIGH 7.2
CVE-2024-53564

A vulnerability was discovered in FreePBX 17.0.19.17. It does not verify the type of uploaded (valid FreePBX module) files, allowing high-privilege a…

Mitigation only
Fix from $1,950 2024-12-02
Asterisk MEDIUM 5.7
CVE-2024-42491

Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.24.3, 20.9.3, and 21.4.3 of Asterisk and versions 18.9-cert12 and 20.7…

Fix: 18.9 / 18.24.3+
Fix from $1,600 2024-09-05
Asterisk MEDIUM 5.3
CVE-2024-35190

Asterisk is an open source private branch exchange and telephony toolkit. After upgrade to 18.23.0, ALL unauthorized SIP requests are identified as P…

Patch available
Fix from $1,600 2024-05-17
Freepbx HIGH 8.8
CVE-2023-43336

Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified param…

Fix: 15.0.16 / 15.0.18+
Fix from $1,950 2023-11-02
Freepbx Linux 7 HIGH 8.1
CVE-2023-26567

Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global varia…

Mitigation only
Fix from $1,950 2023-04-26
Freepbx MEDIUM 6.1
CVE-2019-25090

A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic. Affected by this issue is some unknown functionality of…

Fix: 13.0.5.4+
Fix from $1,600 2022-12-27
Voicemail MEDIUM 6.1
CVE-2021-4282

A vulnerability was found in FreePBX voicemail. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of th…

Fix: 14.0.6.25+
Fix from $1,600 2022-12-27
Voicemail MEDIUM 5.4
CVE-2021-4283

A vulnerability was found in FreeBPX voicemail. It has been rated as problematic. Affected by this issue is some unknown functionality of the file vi…

Fix: 14.0.6.25+
Fix from $1,600 2022-12-27
Freepbx CRITICAL 9.8
CVE-2020-36630

A vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.ph…

Fix: 14.0.5.21+
Fix from $2,300 2022-12-25
Asterisk HIGH 7.5
CVE-2022-37325

In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c…

Fix: 16.29.1 / 18.15.1+
Fix from $1,950 2022-12-05
Asterisk MEDIUM 6.5
CVE-2022-42705

A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to …

Fix: 16.29.1 / 18.15.1+
Fix from $1,600 2022-12-05
Switchvox MEDIUM 5.3
CVE-2021-45310

Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restrictio…

No fix yet
Fix from $1,600 2022-02-14
Restapps CRITICAL 9.8
CVE-2021-45461EPSS 20%

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbit…

No fix yet
Fix from $2,300 2021-12-22
Restapps CRITICAL 9.8
CVE-2020-10666

The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL vari…

Fix: after 15.0.19.2
Fix from $2,300 2021-05-31
Freepbx HIGH 7.2
CVE-2019-19538

In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that…

Fix: 13.0.92 / 14.0.38.3+
Fix from $1,950 2020-03-16
Freepbx CRITICAL 9.8
CVE-2019-19006 KEVEPSS 37%

Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

Fix: after 15.0.16.26
Fix from $2,300 2019-11-21
Session Border Controller Firmware CRITICAL 9.8
CVE-2019-12147

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username fi…

No fix yet
Fix from $2,300 2019-10-22
Session Border Controller Firmware CRITICAL 9.8
CVE-2019-12148

The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection vulnerabi…

No fix yet
Fix from $2,300 2019-10-22
Asterisk MEDIUM 6.5
CVE-2018-12228EPSS 7%

An issue was discovered in Asterisk Open Source 15.x before 15.4.1. When connected to Asterisk via TCP/TLS, if the client abruptly disconnects, or se…

Fix: 15.4.1+
Fix from $1,600 2018-06-12
Freepbx HIGH 7.2
CVE-2018-6393

FreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the vendor disput…

No fix yet
Fix from $1,950 2018-01-29
Netborder\/vega Session Firmware CRITICAL 9.8
CVE-2017-17430

Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.

Mitigation only
Fix from $2,300 2017-12-07
Asterisk HIGH 7.5
CVE-2017-9358

A memory exhaustion vulnerability exists in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1 and Certified Asterisk 13.13 before 13.13…

Mitigation only
Fix from $1,950 2017-06-02
Freepbx HIGH 7.5
CVE-2012-4869EPSS 70%

The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitrary comma…

Fix: after 2.10
Fix from $1,950 2012-09-06
Freepbx MEDIUM 6.5
CVE-2010-3490EPSS 9%

Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interface in FreePBX 2.8.0 and earli…

Fix: after 2.8.0
Fix from $1,600 2010-09-28
Wanpipe HIGH 10.0
CVE-2008-6598

Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."

No fix yet
Fix from $1,950 2009-04-03