Protection mechanism failure in Asterisk Open Source and Certified Asterisk - CVE-2025-47780
Published: May 26, 2025
Vulnerability identifier: #VU109794
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-47780
CWE-ID: CWE-693
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to permissions to deny command execution via the "cli_permissions.conf" file do not work as expected. A local user with access to Asterisk CLI can still execute arbitrary OS commands even if the current configuration disallows it.
Affected software
Asterisk Open Source
Certified Asterisk
Certified Asterisk
How to mitigate CVE-2025-47780
Install updates from vendor's website.
Asterisk Open Source - addressed in versions 18.26.2, 20.14.1, 21.9.1, 22.4.1
Certified Asterisk - addressed in versions 18.9-cert14, 20.7-cert5
Certified Asterisk - addressed in versions 18.9-cert14, 20.7-cert5