CVE-2024-57520
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 5, 2025
Updated: Feb 6, 2025
CWE ID 732
Summary
CVE-2024-57520 is a newly disclosed vulnerability affecting the asterisk v22 communications software. This issue involves insecure permissions, enabling a remote attacker to exploit the action_createconfig function and execute arbitrary code. The vulnerability poses a significant risk, as it allows unauthorized access and potential system takeover. Asterisk users running version v22 are strongly advised to apply the forthcoming patch or upgrade to a secure version to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Digium Asterisk
Affected Vendors
- Digium