Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2014-8418

The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.

  • Published: Nov 24, 2014
  • Updated: Apr 13, 2023
  • CVE: CVE-2014-8418
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9
  • AV:N/AC:L/Au:S/C:C/I:C/A:C

CWEs:

Software From Fixed in
digium / certified_asterisk 11.6-cert6 11.6-cert6.x
digium / certified_asterisk 11.6-cert3 11.6-cert3.x
digium / certified_asterisk 1.8.28-cert2 1.8.28-cert2.x
digium / certified_asterisk 1.8.28-cert1 1.8.28-cert1.x
digium / certified_asterisk 11.6-cert1 11.6-cert1.x
digium / certified_asterisk 11.6.0 11.6.0.x
digium / certified_asterisk 11.6-cert2 11.6-cert2.x
digium / certified_asterisk 1.8.28 1.8.28.x
digium / certified_asterisk 11.6-cert4 11.6-cert4.x
digium / certified_asterisk 11.6-cert5 11.6-cert5.x
digium / certified_asterisk 11.6-cert7 11.6-cert7.x
digium / certified_asterisk 1.8.28-cert1-rc1 1.8.28-cert1-rc1.x
digium / certified_asterisk 1.8.28-cert3 1.8.28-cert3.x
digium / certified_asterisk 1.8.28-cert4 1.8.28-cert4.x
digium / certified_asterisk 1.8.28-cert5 1.8.28-cert5.x
digium / asterisk 11.0.0 11.14.1
digium / asterisk 12.0.0 12.7.1
digium / asterisk 1.8.0 1.8.32.0.x