CVE-2019-19006 is a critical incorrect access control vulnerability affecting Sangoma FreePBX versions 115.0.16.26 and below, 14.0.13.11 and below, and 13.0.197.13 and below. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without authentication, allowing for complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as indicated by its presence in the KEV catalog, and has garnered significant media attention, though public exploit code like Metasploit or Nuclei modules are not currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.0.0.0, <= 13.0.197.13CPE matchmatch criteria | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | ||
>= 14.0.0.0, <= 14.0.13.11CPE matchmatch criteria | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | ||
>= 15.0.0.0, <= 15.0.16.26CPE matchmatch criteria | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.