CVE-2019-19492: Critical severity freeswitch vulnerability
Published Dec 2, 2019
·Updated
FreeSWITCH 1.6.10 through 1.10.1 has a default password in eventsocket.conf.xml.
Affected Software
1 affected component
FreeSWITCH FreeSWITCH>=1.6.10<=1.10.1
Event History
Dec 2, 2019
CVE Published
via MITRE·01:13 AM
Data Sourced
via MITRE·01:13 AM
Description
Frequently Asked Questions
1
What is CVE-2019-19492?
CVE-2019-19492 is a vulnerability in FreeSWITCH 1.6.10 through 1.10.1 that allows unauthorized access due to a default password in event_socket.conf.xml.
2
How severe is CVE-2019-19492?
CVE-2019-19492 is considered critical, with a severity score of 9.8.
3
How does CVE-2019-19492 affect FreeSWITCH?
CVE-2019-19492 affects FreeSWITCH versions 1.6.10 through 1.10.1 by exposing a default password in event_socket.conf.xml, which can lead to unauthorized access.
4
How can I fix CVE-2019-19492?
To fix CVE-2019-19492, it is recommended to update FreeSWITCH to a version that no longer has the default password in event_socket.conf.xml.
5
Where can I find more information about CVE-2019-19492?
You can find more information about CVE-2019-19492 at the following link: [https://www.exploit-db.com/exploits/47698]