Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2012-2186

Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asterisk 1.8.11 before 1.8.11-cert6, Asterisk Digiumphones 10.x.x-digiumphones before 10.7.1-digiumphones, and Asterisk Business Edition C.3.x before C.3.7.6 allows remote authenticated users to execute arbitrary commands by leveraging originate privileges and providing an ExternalIVR value in an AMI Originate action.

  • Published: Aug 31, 2012
  • Updated: Apr 13, 2023
  • CVE: CVE-2012-2186
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9
  • AV:N/AC:L/Au:S/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
asterisk / open_source 1.8.10.0-rc1 1.8.10.0-rc1.x
asterisk / open_source 1.8.0-beta1 1.8.0-beta1.x
asterisk / open_source 1.8.3 1.8.3.x
asterisk / open_source 1.8.8.1 1.8.8.1.x
asterisk / open_source 1.8.1-rc1 1.8.1-rc1.x
asterisk / open_source 1.8.0-rc2 1.8.0-rc2.x
asterisk / open_source 1.8.9.0-rc1 1.8.9.0-rc1.x
asterisk / open_source 1.8.10.0-rc2 1.8.10.0-rc2.x
asterisk / open_source 1.8.0-rc3 1.8.0-rc3.x
asterisk / open_source 1.8.8.0-rc4 1.8.8.0-rc4.x
asterisk / open_source 1.8.0-beta2 1.8.0-beta2.x
asterisk / open_source 1.8.4.4 1.8.4.4.x
asterisk / open_source 1.8.8.0-rc3 1.8.8.0-rc3.x
asterisk / open_source 1.8.11.0 1.8.11.0.x
asterisk / open_source 1.8.3-rc3 1.8.3-rc3.x
asterisk / open_source 1.8.11.0-rc3 1.8.11.0-rc3.x
asterisk / open_source 1.8.2.3 1.8.2.3.x
asterisk / open_source 1.8.0-rc1 1.8.0-rc1.x
asterisk / open_source 1.8.9.0-rc2 1.8.9.0-rc2.x
asterisk / open_source 1.8.7.2 1.8.7.2.x
asterisk / open_source 1.8.9.2 1.8.9.2.x
asterisk / open_source 1.8.0-beta3 1.8.0-beta3.x
asterisk / open_source 1.8.4-rc1 1.8.4-rc1.x
asterisk / open_source 1.8.9.3 1.8.9.3.x
asterisk / open_source 1.8.12.0-rc3 1.8.12.0-rc3.x
asterisk / open_source 1.8.6.0-rc3 1.8.6.0-rc3.x
asterisk / open_source 1.8.6.0-rc2 1.8.6.0-rc2.x
asterisk / open_source 1.8.7.0-rc2 1.8.7.0-rc2.x
asterisk / open_source 1.8.10.0-rc3 1.8.10.0-rc3.x
asterisk / open_source 1.8.3-rc2 1.8.3-rc2.x
asterisk / open_source 1.8.3.3 1.8.3.3.x
asterisk / open_source 1.8.8.0-rc1 1.8.8.0-rc1.x
asterisk / open_source 1.8.6.0 1.8.6.0.x
asterisk / open_source 1.8.12.0 1.8.12.0.x
asterisk / open_source 1.8.8.0-rc2 1.8.8.0-rc2.x
asterisk / open_source 1.8.4.3 1.8.4.3.x
asterisk / open_source 1.8.5.0 1.8.5.0.x
asterisk / open_source 1.8.4.2 1.8.4.2.x
asterisk / open_source 1.8.9.0-rc3 1.8.9.0-rc3.x
asterisk / open_source 1.8.12 1.8.12.x
asterisk / open_source 1.8.12.0-rc2 1.8.12.0-rc2.x
asterisk / open_source 1.8.7.0 1.8.7.0.x
asterisk / open_source 1.8.2.4 1.8.2.4.x
asterisk / open_source 1.8.4.1 1.8.4.1.x
asterisk / open_source 1.8.2 1.8.2.x
asterisk / open_source 1.8.1.2 1.8.1.2.x
asterisk / open_source 1.8.0 1.8.0.x
asterisk / open_source 1.8.3-rc1 1.8.3-rc1.x
asterisk / open_source 1.8.10.0 1.8.10.0.x
asterisk / open_source 1.8.2.1 1.8.2.1.x
asterisk / open_source 1.8.8.0 1.8.8.0.x
asterisk / open_source 1.8.7.1 1.8.7.1.x
asterisk / open_source 1.8.11.1 1.8.11.1.x
asterisk / open_source 1.8.1.1 1.8.1.1.x
asterisk / open_source 1.8.11.0-rc2 1.8.11.0-rc2.x
asterisk / open_source 1.8.7.0-rc1 1.8.7.0-rc1.x
asterisk / open_source 1.8.0-beta4 1.8.0-beta4.x
asterisk / open_source 1.8.8.0-rc5 1.8.8.0-rc5.x
asterisk / open_source 1.8.0-rc4 1.8.0-rc4.x
asterisk / open_source 1.8.4-rc3 1.8.4-rc3.x
asterisk / open_source 1.8.4-rc2 1.8.4-rc2.x
asterisk / open_source 1.8.0-rc5 1.8.0-rc5.x
asterisk / open_source 1.8.1 1.8.1.x
asterisk / open_source 1.8.9.1 1.8.9.1.x
asterisk / open_source 1.8.6.0-rc1 1.8.6.0-rc1.x
asterisk / open_source 1.8.10.1 1.8.10.1.x
asterisk / open_source 1.8.3.1 1.8.3.1.x
asterisk / open_source 1.8.7 1.8.7.x
asterisk / open_source 1.8.9.0 1.8.9.0.x
asterisk / open_source 1.8.2-rc1 1.8.2-rc1.x
asterisk / open_source 1.8.10.0-rc4 1.8.10.0-rc4.x
asterisk / open_source 1.8.4 1.8.4.x
asterisk / open_source 1.8.3.2 1.8.3.2.x
asterisk / open_source 1.8.12.0-rc1 1.8.12.0-rc1.x
asterisk / open_source 1.8.5-rc1 1.8.5-rc1.x
asterisk / open_source 1.8.2.2 1.8.2.2.x
asterisk / open_source 1.8.0-beta5 1.8.0-beta5.x
asterisk / open_source 1.8.8.2 1.8.8.2.x
asterisk / open_source 10.2.0-rc2 10.2.0-rc2.x
asterisk / open_source 10.3.0 10.3.0.x
asterisk / open_source 10.2.0-rc1 10.2.0-rc1.x
asterisk / open_source 10.4.0-rc3 10.4.0-rc3.x
asterisk / open_source 10.3 10.3.x
asterisk / open_source 10.3.0-rc3 10.3.0-rc3.x
asterisk / open_source 10.1.0 10.1.0.x
asterisk / open_source 10.2.1 10.2.1.x
asterisk / open_source 10.2.0-rc4 10.2.0-rc4.x
asterisk / open_source 10.3.1 10.3.1.x
asterisk / open_source 10.3.0-rc2 10.3.0-rc2.x
asterisk / open_source 10.4.0-rc1 10.4.0-rc1.x
asterisk / open_source 10.1.0-rc1 10.1.0-rc1.x
asterisk / open_source 10.4.0 10.4.0.x
asterisk / open_source 10.0.0 10.0.0.x
asterisk / open_source 10.2.0-rc3 10.2.0-rc3.x
asterisk / open_source 10.1.1 10.1.1.x
asterisk / open_source 10.0.0-beta1 10.0.0-beta1.x
asterisk / open_source 10.2.0 10.2.0.x
asterisk / open_source 10.0.0-rc2 10.0.0-rc2.x
asterisk / open_source 10.1.2 10.1.2.x
asterisk / open_source 10.0.0-rc3 10.0.0-rc3.x
asterisk / open_source 10.1.0-rc2 10.1.0-rc2.x
asterisk / open_source 10.0.1 10.0.1.x
asterisk / open_source 10.0.0-rc1 10.0.0-rc1.x
asterisk / open_source 10.1.3 10.1.3.x
asterisk / open_source 10.4.0-rc2 10.4.0-rc2.x
asterisk / open_source 10.0.0-beta2 10.0.0-beta2.x
asterisk / certified_asterisk 1.8.11-cert3 1.8.11-cert3.x
asterisk / certified_asterisk 1.8.11-cert 1.8.11-cert.x
asterisk / certified_asterisk 1.8.11-cert2 1.8.11-cert2.x
asterisk / certified_asterisk - 1.8.11.x
asterisk / certified_asterisk 1.8.11-cert1 1.8.11-cert1.x
asterisk / certified_asterisk 1.8.11-cert4 1.8.11-cert4.x
asterisk / digiumphones - 10.7.0.x
asterisk / business_edition c.3.0 c.3.0.x
asterisk / business_edition - c.3.7.5.x
sangoma / asterisk - 1.8.15.0.x
sangoma / asterisk - 10.7.0.x