First published: Wed Dec 22 2021(Updated: )
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sangoma Restapps | =15.0.19.87 | |
Sangoma Restapps | =15.0.19.88 | |
Sangoma Restapps | =16.0.18.40 | |
Sangoma Restapps | =16.0.18.41 | |
Sangoma FreePBX | ||
Sangoma Pbxact |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45461 is a vulnerability in FreePBX when restapps (aka Rest Phone Apps) version 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed.
CVE-2021-45461 is rated as critical with a severity score of 9.8 out of 10.
An attacker exploiting CVE-2021-45461 can execute arbitrary code on the affected system.
Versions 15.0.19.87, 15.0.19.88, 16.0.18.40, and 16.0.18.41 of restapps are affected by CVE-2021-45461.
To fix CVE-2021-45461, update to the fixed versions: 15.0.20 and 16.0.19 of restapps.