CVE-2012-2414
NONE EPSS 84.2%
Published Apr 30, 201214y ago · Modified Jun 16, 20262w ago
Published Apr 30, 2012 14y ago
Last Modified Jun 16, 2026 2w ago
Description
main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.
Threat Intelligence
EPSS Exploit Probability
84.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-287 Improper Authentication Authentication
Affected Products 153
| Vendor | Product | Version | Range |
|---|---|---|---|
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.0 | any |
| asterisk | open_source | 1.6.2.1 | any |
| asterisk | open_source | 1.6.2.1 | any |
| asterisk | open_source | 1.6.2.2 | any |
| asterisk | open_source | 1.6.2.3 | any |
| asterisk | open_source | 1.6.2.4 | any |
| asterisk | open_source | 1.6.2.5 | any |
| asterisk | open_source | 1.6.2.6 | any |
| asterisk | open_source | 1.6.2.6 | any |
| asterisk | open_source | 1.6.2.6 | any |
| asterisk | open_source | 1.6.2.7 | any |
| asterisk | open_source | 1.6.2.7 | any |
| asterisk | open_source | 1.6.2.7 | any |
| asterisk | open_source | 1.6.2.7 | any |
| asterisk | open_source | 1.6.2.8 | any |
| asterisk | open_source | 1.6.2.8 | any |
| asterisk | open_source | 1.6.2.9 | any |
| asterisk | open_source | 1.6.2.9 | any |
| asterisk | open_source | 1.6.2.9 | any |
| asterisk | open_source | 1.6.2.9 | any |
| asterisk | open_source | 1.6.2.10 | any |
| asterisk | open_source | 1.6.2.10 | any |
| asterisk | open_source | 1.6.2.10 | any |
| asterisk | open_source | 1.6.2.11 | any |
| asterisk | open_source | 1.6.2.11 | any |
| asterisk | open_source | 1.6.2.11 | any |
| asterisk | open_source | 1.6.2.12 | any |
| asterisk | open_source | 1.6.2.12 | any |
| asterisk | open_source | 1.6.2.13 | any |
| asterisk | open_source | 1.6.2.14 | any |
| asterisk | open_source | 1.6.2.14 | any |
| asterisk | open_source | 1.6.2.15 | any |
| asterisk | open_source | 1.6.2.15 | any |
| asterisk | open_source | 1.6.2.15.1 | any |
| asterisk | open_source | 1.6.2.16 | any |
| asterisk | open_source | 1.6.2.16 | any |
| asterisk | open_source | 1.6.2.16.1 | any |
| asterisk | open_source | 1.6.2.16.2 | any |
| asterisk | open_source | 1.6.2.17 | any |
| asterisk | open_source | 1.6.2.17 | any |
| asterisk | open_source | 1.6.2.17 | any |
| asterisk | open_source | 1.6.2.17 | any |
| asterisk | open_source | 1.6.2.17.1 | any |
| asterisk | open_source | 1.6.2.17.2 | any |
| asterisk | open_source | 1.6.2.17.3 | any |
| asterisk | open_source | 1.6.2.18 | any |
| asterisk | open_source | 1.6.2.18 | any |
| asterisk | open_source | 1.6.2.18.1 | any |
| asterisk | open_source | 1.6.2.18.2 | any |
| asterisk | open_source | 1.6.2.19 | any |
| asterisk | open_source | 1.6.2.19 | any |
| asterisk | open_source | 1.6.2.20 | any |
| asterisk | open_source | 1.6.2.21 | any |
| asterisk | open_source | 1.6.2.22 | any |
| asterisk | open_source | 1.6.2.23 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.0 | any |
| asterisk | open_source | 1.8.1 | any |
| asterisk | open_source | 1.8.1 | any |
| asterisk | open_source | 1.8.1.1 | any |
| asterisk | open_source | 1.8.1.2 | any |
| asterisk | open_source | 1.8.2 | any |
| asterisk | open_source | 1.8.2 | any |
| asterisk | open_source | 1.8.2.1 | any |
| asterisk | open_source | 1.8.2.2 | any |
| asterisk | open_source | 1.8.2.3 | any |
| asterisk | open_source | 1.8.2.4 | any |
| asterisk | open_source | 1.8.3 | any |
| asterisk | open_source | 1.8.3 | any |
| asterisk | open_source | 1.8.3 | any |
| asterisk | open_source | 1.8.3 | any |
| asterisk | open_source | 1.8.3.1 | any |
| asterisk | open_source | 1.8.3.2 | any |
| asterisk | open_source | 1.8.3.3 | any |
| asterisk | open_source | 1.8.4 | any |
| asterisk | open_source | 1.8.4 | any |
| asterisk | open_source | 1.8.4 | any |
| asterisk | open_source | 1.8.4 | any |
| asterisk | open_source | 1.8.4.1 | any |
| asterisk | open_source | 1.8.4.2 | any |
| asterisk | open_source | 1.8.4.3 | any |
| asterisk | open_source | 1.8.4.4 | any |
| asterisk | open_source | 1.8.5 | any |
| asterisk | open_source | 1.8.5.0 | any |
| asterisk | open_source | 1.8.6.0 | any |
| asterisk | open_source | 1.8.6.0 | any |
| asterisk | open_source | 1.8.6.0 | any |
| asterisk | open_source | 1.8.6.0 | any |
| asterisk | open_source | 1.8.7.0 | any |
| asterisk | open_source | 1.8.7.0 | any |
| asterisk | open_source | 1.8.7.0 | any |
| asterisk | open_source | 1.8.7.1 | any |
| asterisk | open_source | 1.8.7.2 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.0 | any |
| asterisk | open_source | 1.8.8.1 | any |
| asterisk | open_source | 1.8.8.2 | any |
| asterisk | open_source | 1.8.9.0 | any |
| asterisk | open_source | 1.8.9.0 | any |
| asterisk | open_source | 1.8.9.0 | any |
| asterisk | open_source | 1.8.9.0 | any |
| asterisk | open_source | 1.8.9.1 | any |
| asterisk | open_source | 1.8.9.2 | any |
| asterisk | open_source | 1.8.9.3 | any |
| asterisk | open_source | 1.8.10.0 | any |
| asterisk | open_source | 1.8.10.0 | any |
| asterisk | open_source | 1.8.10.0 | any |
| asterisk | open_source | 1.8.10.0 | any |
| asterisk | open_source | 1.8.10.0 | any |
| asterisk | open_source | 1.8.10.1 | any |
| asterisk | open_source | 1.8.11.0 | any |
| asterisk | open_source | 1.8.11.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.0 | any |
| asterisk | open_source | 10.0.1 | any |
| asterisk | open_source | 10.1.0 | any |
| asterisk | open_source | 10.1.0 | any |
| asterisk | open_source | 10.1.0 | any |
| asterisk | open_source | 10.1.1 | any |
| asterisk | open_source | 10.1.2 | any |
| asterisk | open_source | 10.1.3 | any |
| asterisk | open_source | 10.2.0 | any |
| asterisk | open_source | 10.2.0 | any |
| asterisk | open_source | 10.2.0 | any |
| asterisk | open_source | 10.2.0 | any |
| asterisk | open_source | 10.2.0 | any |
| asterisk | open_source | 10.2.1 | any |
| asterisk | open_source | 10.3.0 | any |
| asterisk | open_source | 10.3.0 | any |
| asterisk | open_source | 10.3.0 | any |
References 9
- downloads.asterisk.org http://downloads.asterisk.org/pub/security/AST-2012-004.html
- lists.fedoraproject.org http://lists.fedoraproject.org/pipermail/package-announce/2012-May/079759.html
- osvdb.org http://osvdb.org/81454
- secunia.com http://secunia.com/advisories/48891
- secunia.com http://secunia.com/advisories/48941
- debian.org http://www.debian.org/security/2012/dsa-2460
- securityfocus.com http://www.securityfocus.com/bid/53206
- securitytracker.com http://www.securitytracker.com/id?1026961
- exchange.xforce.ibmcloud.com https://exchange.xforce.ibmcloud.com/vulnerabilities/75100
Remediation
- downloads.asterisk.org http://downloads.asterisk.org/pub/security/AST-2012-004.html