CVE-2024-42365 describes a critical vulnerability in Asterisk and Certified Asterisk versions prior to 18.24.2, 20.9.2, 21.4.2, 18.9-cert11, and 20.7-cert2, respectively. An authenticated AMI user with write=originate permissions can manipulate configuration files in /etc/asterisk/ by curling remote files and appending to existing ones. This flaw carries a CVSS score of 8.8 (High), indicating a network-exploitable vulnerability with low attack complexity that can lead to privilege escalation, remote code execution, and blind server-side request forgery. While not currently on the CISA KEV list or experiencing widespread community discussion, a Metasploit module for authenticated RCE exists, suggesting potential for exploitation. Organizations using affected Asterisk versions should prioritize patching to mitigate these severe risks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.24.2CPE matchmatch criteria | cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:* | ||
>= 19.0.0, < 20.9.1CPE matchmatch criteria | cpe:2.3:a:asterisk:asterisk:*:*:*:*:*:*:*:* | ||
21.4.0CPE matchmatch criteria | cpe:2.3:a:asterisk:asterisk:21.4.0:*:*:*:*:*:*:* | ||
13.13.0CPE matchmatch criteria | cpe:2.3:a:asterisk:certified_asterisk:13.13.0:*:*:*:*:*:*:* | ||
13.13.0CPE matchmatch criteria | cpe:2.3:a:asterisk:certified_asterisk:13.13.0:cert1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.