CVE-2020-7351
Fonality Trixbox CE Post-Authentication Command Injection
Vexday Risk Score
48Attention
SSVC decision (CISA)
Attend
PoC available → attend closely
CVSS 7.3EPSS 65.2%KEV nãoPoC —Nuclei —Metasploit simPatch —
Lifecycle
28 Apr 2020Metasploit module available
01 May 2020Published on NVD
Recommendation: Plan a near-term fix — a public PoC already exists.
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Affected products
Fonality · Trixbox Community EditionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →