CVE-2014-8418: Critical severity digium asterisk appliance developer kit vulnerability
The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-8418?
CVE-2014-8418 is considered a medium severity vulnerability allowing privilege escalation for remote authenticated users.
How do I fix CVE-2014-8418?
To fix CVE-2014-8418, you should upgrade Asterisk to the latest version or at least to versions 1.8.32, 11.1.4.1, 12.7.1, or 13.0.1.
Who is affected by CVE-2014-8418?
CVE-2014-8418 affects all versions of Asterisk prior to 1.8.32, 11.1.4.1, 12.7.1, and 13.0.1.
Can CVE-2014-8418 be exploited over the Internet?
Yes, CVE-2014-8418 can be exploited over the Internet if an attacker can authenticate as a remote user.
What type of vulnerability is CVE-2014-8418?
CVE-2014-8418 is a privilege escalation vulnerability that allows unauthorized access through a call from an external protocol.