CVE-2021-45461

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:sangoma:restapps:15.0.19.87:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:15.0.19.88:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:16.0.18.40:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:16.0.18.41:*:*:*:*:*:*:*
OR cpe:2.3:a:sangoma:freepbx:-:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:pbxact:-:*:*:*:*:*:*:*

History

05 Jan 2022, 17:39

Type Values Removed Values Added
References (CONFIRM) https://community.freepbx.org/t/security-issue-potential-rest-phone-apps-rce/80109 - (CONFIRM) https://community.freepbx.org/t/security-issue-potential-rest-phone-apps-rce/80109 - Vendor Advisory
References (CONFIRM) https://wiki.freepbx.org/display/FOP/2021-12-21+SECURITY%3A+Potential+Rest+Phone+Apps+RCE - (CONFIRM) https://wiki.freepbx.org/display/FOP/2021-12-21+SECURITY%3A+Potential+Rest+Phone+Apps+RCE - Vendor Advisory
References (MISC) https://community.freepbx.org/t/0-day-freepbx-exploit/80092 - (MISC) https://community.freepbx.org/t/0-day-freepbx-exploit/80092 - Exploit, Issue Tracking, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
First Time Sangoma freepbx
Sangoma restapps
Sangoma pbxact
Sangoma
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:sangoma:restapps:15.0.19.88:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:16.0.18.40:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:pbxact:-:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:16.0.18.41:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:restapps:15.0.19.87:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:freepbx:-:*:*:*:*:*:*:*

22 Dec 2021, 20:11

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-22 19:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-45461

Mitre link : CVE-2021-45461

CVE.ORG link : CVE-2021-45461


JSON object : View

Products Affected

sangoma

  • freepbx
  • pbxact
  • restapps