CVE-2021-45461: Critical severity Sangoma restapps vulnerability
Published Dec 22, 2021
·Updated
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.
Affected Software
12 affected components
All of the following
Any of the following
Sangoma restapps=15.0.19.87
Sangoma restapps=15.0.19.88
Sangoma restapps=16.0.18.40
Sangoma restapps=16.0.18.41
Any of the following
Sangoma FreePBX
Sangoma Pbxact
Sangoma restapps=15.0.19.87
Sangoma restapps=15.0.19.88
Sangoma restapps=16.0.18.40
Sangoma restapps=16.0.18.41
Sangoma FreePBX
Sangoma Pbxact
Event History
Dec 22, 2021
CVE Published
via MITRE·06:25 PM
Data Sourced
via MITRE·06:25 PM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2021-45461?
CVE-2021-45461 is a vulnerability in FreePBX when restapps (aka Rest Phone Apps) version 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed.
2
How severe is CVE-2021-45461?
CVE-2021-45461 is rated as critical with a severity score of 9.8 out of 10.
3
What can an attacker do with CVE-2021-45461?
An attacker exploiting CVE-2021-45461 can execute arbitrary code on the affected system.
4
Which versions of restapps are affected by CVE-2021-45461?
Versions 15.0.19.87, 15.0.19.88, 16.0.18.40, and 16.0.18.41 of restapps are affected by CVE-2021-45461.
5
How can I fix CVE-2021-45461?
To fix CVE-2021-45461, update to the fixed versions: 15.0.20 and 16.0.19 of restapps.