CVE-2012-2414

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 88%
VendorProductVersion
asteriskopen_source
1.6.2.0
asteriskopen_source
1.6.2.0:rc2
asteriskopen_source
1.6.2.0:rc3
asteriskopen_source
1.6.2.0:rc4
asteriskopen_source
1.6.2.0:rc5
asteriskopen_source
1.6.2.0:rc6
asteriskopen_source
1.6.2.0:rc7
asteriskopen_source
1.6.2.0:rc8
asteriskopen_source
1.6.2.1
asteriskopen_source
1.6.2.1:rc1
asteriskopen_source
1.6.2.2
asteriskopen_source
1.6.2.3:rc2
asteriskopen_source
1.6.2.4
asteriskopen_source
1.6.2.5
asteriskopen_source
1.6.2.6
asteriskopen_source
1.6.2.6:rc1
asteriskopen_source
1.6.2.6:rc2
asteriskopen_source
1.6.2.7
asteriskopen_source
1.6.2.7:rc1
asteriskopen_source
1.6.2.7:rc2
asteriskopen_source
1.6.2.7:rc3
asteriskopen_source
1.6.2.8
asteriskopen_source
1.6.2.8:rc1
asteriskopen_source
1.6.2.9
asteriskopen_source
1.6.2.9:rc1
asteriskopen_source
1.6.2.9:rc2
asteriskopen_source
1.6.2.9:rc3
asteriskopen_source
1.6.2.10
asteriskopen_source
1.6.2.10:rc1
asteriskopen_source
1.6.2.10:rc2
asteriskopen_source
1.6.2.11
asteriskopen_source
1.6.2.11:rc1
asteriskopen_source
1.6.2.11:rc2
asteriskopen_source
1.6.2.12
asteriskopen_source
1.6.2.12:rc1
asteriskopen_source
1.6.2.13
asteriskopen_source
1.6.2.14
asteriskopen_source
1.6.2.14:rc1
asteriskopen_source
1.6.2.15
asteriskopen_source
1.6.2.15:rc1
asteriskopen_source
1.6.2.15.1
asteriskopen_source
1.6.2.16
asteriskopen_source
1.6.2.16:rc1
asteriskopen_source
1.6.2.16.1
asteriskopen_source
1.6.2.16.2
asteriskopen_source
1.6.2.17
asteriskopen_source
1.6.2.17:rc1
asteriskopen_source
1.6.2.17:rc2
asteriskopen_source
1.6.2.17:rc3
asteriskopen_source
1.6.2.17.1
asteriskopen_source
1.6.2.17.2
asteriskopen_source
1.6.2.17.3
asteriskopen_source
1.6.2.18
asteriskopen_source
1.6.2.18:rc1
asteriskopen_source
1.6.2.18.1
asteriskopen_source
1.6.2.18.2
asteriskopen_source
1.6.2.19
asteriskopen_source
1.6.2.19:rc1
asteriskopen_source
1.6.2.20
asteriskopen_source
1.6.2.21
asteriskopen_source
1.6.2.22
asteriskopen_source
1.6.2.23
asteriskopen_source
1.8.0
asteriskopen_source
1.8.0:beta1
asteriskopen_source
1.8.0:beta2
asteriskopen_source
1.8.0:beta3
asteriskopen_source
1.8.0:beta4
asteriskopen_source
1.8.0:beta5
asteriskopen_source
1.8.0:rc2
asteriskopen_source
1.8.0:rc3
asteriskopen_source
1.8.0:rc4
asteriskopen_source
1.8.0:rc5
asteriskopen_source
1.8.1
asteriskopen_source
1.8.1:rc1
asteriskopen_source
1.8.1.1
asteriskopen_source
1.8.1.2
asteriskopen_source
1.8.2
asteriskopen_source
1.8.2:rc1
asteriskopen_source
1.8.2.1
asteriskopen_source
1.8.2.2
asteriskopen_source
1.8.2.3
asteriskopen_source
1.8.2.4
asteriskopen_source
1.8.3
asteriskopen_source
1.8.3:rc1
asteriskopen_source
1.8.3:rc2
asteriskopen_source
1.8.3:rc3
asteriskopen_source
1.8.3.1
asteriskopen_source
1.8.3.2
asteriskopen_source
1.8.3.3
asteriskopen_source
1.8.4
asteriskopen_source
1.8.4:rc1
asteriskopen_source
1.8.4:rc2
asteriskopen_source
1.8.4:rc3
asteriskopen_source
1.8.4.1
asteriskopen_source
1.8.4.2
asteriskopen_source
1.8.4.3
asteriskopen_source
1.8.4.4
asteriskopen_source
1.8.5:rc1
asteriskopen_source
1.8.5.0
asteriskopen_source
1.8.6.0
asteriskopen_source
1.8.6.0:rc1
asteriskopen_source
1.8.6.0:rc2
asteriskopen_source
1.8.6.0:rc3
asteriskopen_source
1.8.7.0
asteriskopen_source
1.8.7.0:rc1
asteriskopen_source
1.8.7.0:rc2
asteriskopen_source
1.8.7.1
asteriskopen_source
1.8.7.2
asteriskopen_source
1.8.8.0
asteriskopen_source
1.8.8.0:rc1
asteriskopen_source
1.8.8.0:rc2
asteriskopen_source
1.8.8.0:rc3
asteriskopen_source
1.8.8.0:rc4
asteriskopen_source
1.8.8.0:rc5
asteriskopen_source
1.8.8.1
asteriskopen_source
1.8.8.2
asteriskopen_source
1.8.9.0
asteriskopen_source
1.8.9.0:rc1
asteriskopen_source
1.8.9.0:rc2
asteriskopen_source
1.8.9.0:rc3
asteriskopen_source
1.8.9.1
asteriskopen_source
1.8.9.2
asteriskopen_source
1.8.9.3
asteriskopen_source
1.8.10.0
asteriskopen_source
1.8.10.0:rc1
asteriskopen_source
1.8.10.0:rc2
asteriskopen_source
1.8.10.0:rc3
asteriskopen_source
1.8.10.0:rc4
asteriskopen_source
1.8.10.1
asteriskopen_source
1.8.11.0:rc2
asteriskopen_source
1.8.11.0:rc3
asteriskopen_source
10.0.0
asteriskopen_source
10.0.0:beta1
asteriskopen_source
10.0.0:beta2
asteriskopen_source
10.0.0:rc1
asteriskopen_source
10.0.0:rc2
asteriskopen_source
10.0.0:rc3
asteriskopen_source
10.0.1
asteriskopen_source
10.1.0
asteriskopen_source
10.1.0:rc1
asteriskopen_source
10.1.0:rc2
asteriskopen_source
10.1.1
asteriskopen_source
10.1.2
asteriskopen_source
10.1.3
asteriskopen_source
10.2.0
asteriskopen_source
10.2.0:rc1
asteriskopen_source
10.2.0:rc2
asteriskopen_source
10.2.0:rc3
asteriskopen_source
10.2.0:rc4
asteriskopen_source
10.2.1
asteriskopen_source
10.3.0
asteriskopen_source
10.3.0:rc2
asteriskopen_source
10.3.0:rc3
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
1:16.28.0~dfsg-0+deb11u4
fixed
bullseye (security)
1:16.28.0~dfsg-0+deb11u5
fixed
sid
1:22.0.0~dfsg+~cs6.14.60671435-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
asterisk
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
dne
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
ignored
oneiric
ignored
natty
ignored
lucid
ignored
hardy
not-affected