Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-14 12:39
Updated : 2024-07-03 01:39
NVD link : CVE-2023-26566
Mitre link : CVE-2023-26566
CVE.ORG link : CVE-2023-26566
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials