CVE-2023-43336: High severity Sangoma FreePBX vulnerability
Published Nov 2, 2023
·Updated
Sangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified parameter value, e.g., changing extension=self to extension=101.
Affected Software
4 affected components
Sangoma FreePBX <15.0.16
Sangoma FreePBX >=16.0.2<16.0.17
FreePBX<15.0.18
FreePBX>=16.0.2<16.0.40
Event History
Nov 2, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-43336.
2
What is the severity level of CVE-2023-43336?
The severity level of CVE-2023-43336 is high with a severity value of 8.8.
3
What is the affected software?
Sangoma Technologies FreePBX versions before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 are affected.
4
What is the access control issue in CVE-2023-43336?
CVE-2023-43336 contains an access control issue via a modified parameter value, such as changing extension=self to extension=101.
5
How can I fix CVE-2023-43336?
To fix CVE-2023-43336, it is recommended to update Sangoma Technologies FreePBX to cdr 15.0.18, 16.0.40, 15.0.16, or 16.0.17 depending on the affected version.