CVE-2023-26566: High severity Sangoma FreePBX vulnerability
Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26566?
CVE-2023-26566 is rated as a high severity vulnerability due to its potential to allow remote attackers to reconfigure Asterisk.
How do I fix CVE-2023-26566?
To address CVE-2023-26566, you should update your Sangoma FreePBX version to a patched version released beyond 2203.
What types of attacks can CVE-2023-26566 enable?
CVE-2023-26566 enables attackers to make unauthorized external and internal calls via the Asterisk REST Interface.
Which versions of FreePBX are affected by CVE-2023-26566?
CVE-2023-26566 affects Sangoma FreePBX versions from 1805 through 2203.
Are hardcoded credentials a common issue in CVE-2023-26566?
Yes, hardcoded credentials in CVE-2023-26566 pose significant security risks as they can be exploited by attackers to gain unauthorized access.