CVE-2019-19538: High severity Sangoma FreePBX vulnerability
Published Mar 16, 2020
·Updated
In Sangoma FreePBX 13 through 15 and sysadmin (aka System Admin) 13.0.92 through 15.0.13.6 modules have a Remote Command Execution vulnerability that results in Privilege Escalation.
Affected Software
3 affected components
Sangoma FreePBX <13.0.92
Sangoma FreePBX >=14.0.0.0<14.0.38.3
Sangoma FreePBX >=15.0.0.0<15.0.13.6
Event History
Mar 16, 2020
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
Description
Frequently Asked Questions
1
What is CVE-2019-19538?
CVE-2019-19538 is a Remote Command Execution vulnerability in Sangoma FreePBX 13 through 15 and sysadmin modules.
2
How severe is CVE-2019-19538?
CVE-2019-19538 has a severity score of 7.2, which is considered high.
3
Which software versions are affected by CVE-2019-19538?
Sangoma FreePBX versions 13.0.92 up to exclusive, 14.0.0.0 up to 14.0.38.3 (exclusive), and 15.0.0.0 up to 15.0.13.6 (exclusive) are affected.
4
What is the impact of CVE-2019-19538?
CVE-2019-19538 allows an attacker to execute remote commands, resulting in privilege escalation.
5
How can I fix CVE-2019-19538?
To fix CVE-2019-19538, it is recommended to update the Sangoma FreePBX and sysadmin modules to the latest versions available.