Vulnerabilities > Sangoma

DATE CVE VULNERABILITY TITLE RISK
2023-04-26 CVE-2023-26567 Insufficiently Protected Credentials vulnerability in Sangoma Freepbx Linux 7
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables.
network
low complexity
sangoma CWE-522
8.1
2022-12-27 CVE-2019-25090 Cross-site Scripting vulnerability in Sangoma Freepbx
A vulnerability was found in FreePBX arimanager up to 13.0.5.3 and classified as problematic.
network
low complexity
sangoma CWE-79
6.1
2022-12-27 CVE-2021-4282 Cross-site Scripting vulnerability in Sangoma Voicemail
A vulnerability was found in FreePBX voicemail.
network
low complexity
sangoma CWE-79
6.1
2022-12-27 CVE-2021-4283 Cross-site Scripting vulnerability in Sangoma Voicemail
A vulnerability was found in FreeBPX voicemail.
network
low complexity
sangoma CWE-79
5.4
2022-12-05 CVE-2022-37325 Out-of-bounds Write vulnerability in Sangoma Asterisk
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
network
low complexity
sangoma CWE-787
7.5
2022-12-05 CVE-2022-42705 Use After Free vulnerability in Sangoma Asterisk and Certified Asterisk
A use-after-free in res_pjsip_pubsub.c in Sangoma Asterisk 16.28, 18.14, 19.6, and certified/18.9-cert2 may allow a remote authenticated attacker to crash Asterisk (denial of service) by performing activity on a subscription via a reliable transport at the same time that Asterisk is also performing activity on that subscription.
network
low complexity
sangoma CWE-416
6.5
2022-12-05 CVE-2022-42706 Path Traversal vulnerability in Sangoma Asterisk and Certified Asterisk
An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1.
network
low complexity
sangoma CWE-22
4.9
2022-02-22 CVE-2022-23608 Use After Free vulnerability in multiple products
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE.
network
low complexity
teluu asterisk sangoma debian CWE-416
critical
9.8
2022-02-14 CVE-2021-45310 Information Exposure vulnerability in Sangoma Switchvox 102409
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information disclosure vulnerability due to an improper access restriction.
network
low complexity
sangoma CWE-200
5.0
2022-01-27 CVE-2022-21723 Out-of-bounds Read vulnerability in multiple products
PJSIP is a free and open source multimedia communication library written in C language implementing standard based protocols such as SIP, SDP, RTP, STUN, TURN, and ICE.
network
low complexity
teluu asterisk sangoma debian CWE-125
critical
9.1