CVE-2025-47780
Severity CVSS v4.0:
MEDIUM
Type:
CWE-78
OS Command Injections
Publication date:
22/05/2025
Last modified:
03/11/2025
Description
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
7.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | 18.26.2 (excluding) | |
| cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | 20.0.0 (including) | 20.14.1 (excluding) |
| cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | 21.0.0 (including) | 21.9.1 (excluding) |
| cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:* | 22.0.0 (including) | 22.4.1 (excluding) |
| cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:* | 18.9 (excluding) | |
| cpe:2.3:a:sangoma:certified_asterisk:18.9:-:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:* | ||
| cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



