CVE Vulnerabilities

CVE-2021-45461

Published: Dec 22, 2021 | Modified: Jan 05, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.

Affected Software

Name Vendor Start Version End Version
Restapps Sangoma 15.0.19.87 (including) 15.0.19.87 (including)
Restapps Sangoma 15.0.19.88 (including) 15.0.19.88 (including)
Restapps Sangoma 16.0.18.40 (including) 16.0.18.40 (including)
Restapps Sangoma 16.0.18.41 (including) 16.0.18.41 (including)

References