CVE-2014-8418

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:S/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
VendorProductVersion
digiumcertified_asterisk
1.8.28
digiumcertified_asterisk
1.8.28:cert1
digiumcertified_asterisk
1.8.28:cert1-rc1
digiumcertified_asterisk
1.8.28:cert2
digiumcertified_asterisk
1.8.28:cert2
digiumcertified_asterisk
1.8.28:cert3
digiumcertified_asterisk
1.8.28:cert4
digiumcertified_asterisk
1.8.28:cert5
digiumcertified_asterisk
11.6:cert1
digiumcertified_asterisk
11.6:cert2
digiumcertified_asterisk
11.6:cert3
digiumcertified_asterisk
11.6:cert4
digiumcertified_asterisk
11.6:cert5
digiumcertified_asterisk
11.6:cert6
digiumcertified_asterisk
11.6:cert7
digiumcertified_asterisk
11.6.0
digiumasterisk
1.8.0 ≤
𝑥
≤ 1.8.32.0
digiumasterisk
11.0.0 ≤
𝑥
< 11.14.1
digiumasterisk
12.0.0 ≤
𝑥
< 12.7.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
asterisk
bullseye
1:16.28.0~dfsg-0+deb11u4
fixed
bullseye (security)
1:16.28.0~dfsg-0+deb11u5
fixed
sid
1:22.0.0~dfsg+~cs6.14.60671435-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
asterisk
disco
not-affected
cosmic
not-affected
bionic
not-affected
artful
not-affected
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
ignored
trusty
dne
precise
ignored
lucid
ignored
Common Weakness Enumeration