Vulnerability identifier: #VU22287
Vulnerability risk: Medium
CVSSv3.1: 7.9 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-77
Exploitation vector: Network
Exploit availability: Yes
Vulnerable software:
FusionPBX
Server applications /
SCADA systems
Vendor: FusionPBX
Description
Mitigation
Install updates from vendor's website.
Vulnerable software versions
FusionPBX: Master
External links
http://drive.google.com/file/d/1bt08NSUaxu87LJJGdNd7LpvZ2uGauRK8/view?usp=sharing
http://gist.github.com/mhaskar/7a6a804cd68c7fec4f9d1f5c3507900f
http://shells.systems/fusionpbx-v4-4-8-authenticated-remote-code-execution-cve-2019-15029/
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.