CVE-2025-47780

Name
CVE-2025-47780
Description
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://github.com/asterisk/asterisk/security/advisories/GHSA-c7p6-7mvq-8jq2

Match rules

CPE URI Source package Min version Max version
asterisk >= 0 < 18.9-cert14
asterisk >= 18.10 < 18.26.2
asterisk >= 20.0 < 20.7-cert5
asterisk >= 20.8 < 20.14.1
asterisk >= 21.0 < 21.9.1
asterisk >= 22.0 < 22.4.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
asterisk edge-main 20.11.0-r0 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.0-r1 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.1-r0 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.1-r1 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.1-r3 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.1-r4 Timo Teras <timo.teras@iki.fi> possibly vulnerable
asterisk edge-main 20.11.1-r5 Timo Teras <timo.teras@iki.fi> possibly vulnerable