Protection mechanism failure in Asterisk Open Source and Certified Asterisk - CVE-2025-47780

 

Protection mechanism failure in Asterisk Open Source and Certified Asterisk - CVE-2025-47780

Published: May 26, 2025


Vulnerability identifier: #VU109794
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47780
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to permissions to deny command execution via the "cli_permissions.conf" file do not work as expected. A local user with access to Asterisk CLI can still execute arbitrary OS commands even if the current configuration disallows it.


Affected software

Asterisk Open Source
Certified Asterisk

How to mitigate CVE-2025-47780

Install updates from vendor's website.

Asterisk Open Source - addressed in versions 18.26.2, 20.14.1, 21.9.1, 22.4.1
Certified Asterisk - addressed in versions 18.9-cert14, 20.7-cert5

External References

Related Security Bulletins