← back
CVE-2020-7351

Fonality Trixbox CE Post-Authentication Command Injection

CVSS 7.3 HIGHEPSS 65.2%CWE-78
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.3EPSS 65.2%KEV nãoPoC Nuclei Metasploit simPatch
Lifecycle
28 Apr 2020Metasploit module available
01 May 2020Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →