ID

VAR-202410-1759


CVE

CVE-2024-49215


TITLE

Sangoma  of  Asterisk  and  certified asterisk  Past traversal vulnerability in

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079

DESCRIPTION

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-49294. Reason: This candidate is a reservation duplicate of CVE-2023-49294. Notes: All CVE users should reference CVE-2023-49294 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. Sangoma of Asterisk and certified asterisk Exists in a past traversal vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state

Trust: 1.62

sources: NVD: CVE-2024-49215 // JVNDB: JVNDB-2024-011079

AFFECTED PRODUCTS

vendor:sangomamodel:asteriskscope: - version: -

Trust: 0.8

vendor:sangomamodel:certified asteriskscope: - version: -

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2024-49215
value: HIGH

Trust: 0.8

NVD: CVE-2024-49215
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079

PROBLEMTYPE DATA

problemtype:Path traversal (CWE-22) [NVD evaluation ]

Trust: 0.8

problemtype: Path traversal (CWE-22) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079

EXTERNAL IDS

db:NVDid:CVE-2024-49215

Trust: 2.6

db:JVNDBid:JVNDB-2024-011079

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079 // NVD: CVE-2024-49215

REFERENCES

url:https://nvd.nist.gov/vuln/detail/cve-2024-49215

Trust: 0.8

url:https://gist.github.com/hyp164d1/5d68b9b7a504f1416272a825ce65966a

Trust: 0.8

url:https://github.com/asterisk/asterisk/blob/20.5.0/main/manager.c#l3755

Trust: 0.8

sources: JVNDB: JVNDB-2024-011079

SOURCES

db:JVNDBid:JVNDB-2024-011079
db:NVDid:CVE-2024-49215

LAST UPDATE DATE

2024-12-10T23:04:47.726000+00:00


SOURCES UPDATE DATE

db:JVNDBid:JVNDB-2024-011079date:2024-10-25T01:12:00
db:NVDid:CVE-2024-49215date:2024-12-09T23:15:08.250

SOURCES RELEASE DATE

db:JVNDBid:JVNDB-2024-011079date:2024-10-25T00:00:00
db:NVDid:CVE-2024-49215date:2024-10-21T01:15:02.943