CVE-2012-2186

EUVD-2012-2180
Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by leveraging originate privileges and providing an ExternalIVR value in an AMI Originate action.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
Base Score
CVSS 3.x
EPSS Score
Percentile: 63%
Affected Products (NVD)
VendorProductVersion
asteriskopen_source
1.8.0
asteriskopen_source
1.8.0:beta1
asteriskopen_source
1.8.0:beta2
asteriskopen_source
1.8.0:beta3
asteriskopen_source
1.8.0:beta4
asteriskopen_source
1.8.0:beta5
asteriskopen_source
1.8.0:rc1
asteriskopen_source
1.8.0:rc2
asteriskopen_source
1.8.0:rc3
asteriskopen_source
1.8.0:rc4
asteriskopen_source
1.8.0:rc5
asteriskopen_source
1.8.1
asteriskopen_source
1.8.1:rc1
asteriskopen_source
1.8.1.1
asteriskopen_source
1.8.1.2
asteriskopen_source
1.8.2
asteriskopen_source
1.8.2:rc1
asteriskopen_source
1.8.2.1
asteriskopen_source
1.8.2.2
asteriskopen_source
1.8.2.3
asteriskopen_source
1.8.2.4
asteriskopen_source
1.8.3
asteriskopen_source
1.8.3:rc1
asteriskopen_source
1.8.3:rc2
asteriskopen_source
1.8.3:rc3
asteriskopen_source
1.8.3.1
asteriskopen_source
1.8.3.2
asteriskopen_source
1.8.3.3
asteriskopen_source
1.8.4
asteriskopen_source
1.8.4:rc1
asteriskopen_source
1.8.4:rc2
asteriskopen_source
1.8.4:rc3
asteriskopen_source
1.8.4.1
asteriskopen_source
1.8.4.2
asteriskopen_source
1.8.4.3
asteriskopen_source
1.8.4.4
asteriskopen_source
1.8.5:rc1
asteriskopen_source
1.8.5.0
asteriskopen_source
1.8.6.0
asteriskopen_source
1.8.6.0:rc1
asteriskopen_source
1.8.6.0:rc2
asteriskopen_source
1.8.6.0:rc3
asteriskopen_source
1.8.7
asteriskopen_source
1.8.7.0
asteriskopen_source
1.8.7.0:rc1
asteriskopen_source
1.8.7.0:rc2
asteriskopen_source
1.8.7.1
asteriskopen_source
1.8.7.2
asteriskopen_source
1.8.8.0
asteriskopen_source
1.8.8.0:rc1
asteriskopen_source
1.8.8.0:rc2
asteriskopen_source
1.8.8.0:rc3
asteriskopen_source
1.8.8.0:rc4
asteriskopen_source
1.8.8.0:rc5
asteriskopen_source
1.8.8.1
asteriskopen_source
1.8.8.2
asteriskopen_source
1.8.9.0
asteriskopen_source
1.8.9.0:rc1
asteriskopen_source
1.8.9.0:rc2
asteriskopen_source
1.8.9.0:rc3
asteriskopen_source
1.8.9.1
asteriskopen_source
1.8.9.2
asteriskopen_source
1.8.9.3
asteriskopen_source
1.8.10.0
asteriskopen_source
1.8.10.0:rc1
asteriskopen_source
1.8.10.0:rc2
asteriskopen_source
1.8.10.0:rc3
asteriskopen_source
1.8.10.0:rc4
asteriskopen_source
1.8.10.1
asteriskopen_source
1.8.11.0
asteriskopen_source
1.8.11.0:rc2
asteriskopen_source
1.8.11.0:rc3
asteriskopen_source
1.8.11.1
asteriskopen_source
1.8.12
asteriskopen_source
1.8.12.0
asteriskopen_source
1.8.12.0:rc1
asteriskopen_source
1.8.12.0:rc2
asteriskopen_source
1.8.12.0:rc3
sangomaasterisk
𝑥
≤ 1.8.15.0
asteriskopen_source
10.0.0
asteriskopen_source
10.0.0:beta1
asteriskopen_source
10.0.0:beta2
asteriskopen_source
10.0.0:rc1
asteriskopen_source
10.0.0:rc2
asteriskopen_source
10.0.0:rc3
asteriskopen_source
10.0.1
asteriskopen_source
10.1.0
asteriskopen_source
10.1.0:rc1
asteriskopen_source
10.1.0:rc2
asteriskopen_source
10.1.1
asteriskopen_source
10.1.2
asteriskopen_source
10.1.3
asteriskopen_source
10.2.0
asteriskopen_source
10.2.0:rc1
asteriskopen_source
10.2.0:rc2
asteriskopen_source
10.2.0:rc3
asteriskopen_source
10.2.0:rc4
asteriskopen_source
10.2.1
asteriskopen_source
10.3
asteriskopen_source
10.3.0
asteriskopen_source
10.3.0:rc2
asteriskopen_source
10.3.0:rc3
asteriskopen_source
10.3.1
asteriskopen_source
10.4.0
asteriskopen_source
10.4.0:rc1
asteriskopen_source
10.4.0:rc2
asteriskopen_source
10.4.0:rc3
sangomaasterisk
𝑥
≤ 10.7.0
asteriskcertified_asterisk
𝑥
≤ 1.8.11
asteriskcertified_asterisk
1.8.11:cert
asteriskcertified_asterisk
1.8.11:cert1
asteriskcertified_asterisk
1.8.11:cert2
asteriskcertified_asterisk
1.8.11:cert3
asteriskcertified_asterisk
1.8.11:cert4
asteriskdigiumphones
𝑥
≤ 10.7.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
1:16.28.0~dfsg-0+deb11u4
fixed
bullseye (security)
1:16.28.0~dfsg-0+deb11u5
fixed
sid
1:22.0.0~dfsg+~cs6.14.60671435-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
asterisk
hardy
not-affected
lucid
not-affected
natty
not-affected
oneiric
ignored
precise
ignored
quantal
not-affected
raring
not-affected
saucy
not-affected
trusty
dne
utopic
not-affected
vivid
not-affected
wily
not-affected
xenial
not-affected
yakkety
not-affected
zesty
not-affected