CVE-2022-42706

moderate-risk
Published 2022-12-05

An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.

Do I need to act?

-
0.81% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
4
CVSS 4.9/10 Medium
NETWORK / LOW complexity

Affected Products (4)

Certified Asterisk
Certified Asterisk

Affected Vendors

33
/ 100
moderate-risk
Severity 20/34 · Moderate
Exploitability 3/34 · Minimal
Exposure 10/34 · Low