CVE-2023-26567: High severity sangoma freepbx vulnerability
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Sangoma FreePBX vulnerability?
The vulnerability ID for this Sangoma FreePBX vulnerability is CVE-2023-26567.
What is the severity of CVE-2023-26567?
The severity of CVE-2023-26567 is high with a CVSS score of 8.1.
How does CVE-2023-26567 affect Sangoma FreePBX?
CVE-2023-26567 exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface in Sangoma FreePBX versions 1805 through 2302.
How can I fix CVE-2023-26567?
To fix CVE-2023-26567, Sangoma FreePBX users should update their software to a version that addresses the vulnerability or apply the necessary security patches.
Where can I find more information about Sangoma FreePBX?
More information about Sangoma FreePBX can be found on the official website at https://www.freepbx.org.