vendor:
FreePBX
by:
muts, SSL update by Emporeo
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: FreePBX
Affected Version From: FreePBX 2.10.0/ 2.9.0, Elastix 2.2.0
Affected Version To: FreePBX 2.10.0/ 2.9.0, Elastix 2.2.0
Patch Exists: YES
Related CWE: notyet
CPE: a:freepbx:freepbx
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Multiple
2012
FreePBX / Elastix pre-authenticated remote code execution exploit
A vulnerability in FreePBX and Elastix allows an attacker to execute arbitrary code on the system without authentication. This exploit was discovered by Martin Tschirsich and was tested on multiple versions of FreePBX and Elastix. The exploit uses a reverse shell payload to connect to a remote host and port, and then uses Nmap to gain root access.
Mitigation:
Ensure that all FreePBX and Elastix systems are updated to the latest version.