Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-30362 | Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call. |
Mon, 03 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-02-03T17:41:54.505Z
Reserved: 2023-02-26T00:00:00.000Z
Link: CVE-2023-26567
Updated: 2024-08-02T11:53:54.579Z
Status : Modified
Published: 2023-04-26T20:15:09.860
Modified: 2025-02-03T18:15:28.833
Link: CVE-2023-26567
No data.
OpenCVE Enrichment
No data.
EUVD