FreePBX.Remote.Admin.Authentication.Bypass

description-logoDescription

This indicates an attack attempt to exploit an Authentication Bypass Vulnerability in FreePBX.
A remote unauthenticated attacker could exploit this vulnerability by sending a crafted request to the vulnerable application. Successful exploitation could lead to the execution privileged commands on the target server.

affected-products-logoAffected Products

FreePBX prior to 15.0.16.26
FreePBX prior to 14.0.13.11
FreePBX prior to 13.0.197.13

Impact logoImpact

Privilege Escalation: Remote attackers can leverage their privileges on vulnerable systems.

recomended-action-logoRecommended Actions

Apply the latest update from the vendor.
https://wiki.freepbx.org/display/FOP/2019-11-20+Remote+Admin+Authentication+Bypass

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2021-01-12 16.996 Default_action:pass:drop
2020-11-25 16.968