CVE-2022-26651 describes a critical SQL injection vulnerability in the func_odbc module of Asterisk through version 19.x and Certified Asterisk through 16.8-cert13. The flaw stems from inadequate escaping of backslash characters in SQL queries, allowing user-provided data to manipulate or break SQL statements. With a CVSS score of 9.8 (Critical), this vulnerability is remotely exploitable with low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, patches are available in Asterisk 16.25.2, 18.11.2, 19.3.2, and Certified Asterisk 16.8-cert14.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 16.0.0, < 16.25.2CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
>= 18.0, < 18.11.2CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
>= 19.0.0, < 19.3.2CPE matchmatch criteria | cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:* | ||
16.8CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:16.8:-:*:*:*:*:*:* | ||
16.8CPE matchmatch criteria | cpe:2.3:a:digium:certified_asterisk:16.8:cert1-rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.