Summary
Authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages in some recent v17 releases of the framework module.
Mitigations
- Update to the latest fixed version of the
framework
module.
- Protect your ACP from suspicious users.
- Remove users that should not have access.
- Firewall your FreePBX ACP HTTP/HTTPS/GraphQL ports.
Scoring
CVSS 4.0 Base vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS 4.0 more complete vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Green
Current CVSS v4.0 Base score is 8.7 (High)
Current CVSS v4.0 more complete score is 6.3 (Medium)
Alternative CVSS v4.1 score is 2 (Low)
See details on scoring on the FreePBX blog at https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80/
Summary
Authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages in some recent v17 releases of the framework module.
Mitigations
framework
module.Scoring
CVSS 4.0 Base vector string:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS 4.0 more complete vector string:
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Green
Current CVSS v4.0 Base score is 8.7 (High)
Current CVSS v4.0 more complete score is 6.3 (Medium)
Alternative CVSS v4.1 score is 2 (Low)
See details on scoring on the FreePBX blog at https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80/