CVE-2019-12147
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.63%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-88
- Affected
- sangoma/session border controller firmware
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Oct/40Exploit, Mailing List, Third Party Advisory
- https://blog.appsecco.comNot Applicable
- http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.htmlExploit, Third Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2019/Oct/40Exploit, Mailing List, Third Party Advisory
- https://blog.appsecco.comNot Applicable
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.