CVE-2021-45461

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute...

Basic Information

CVE State
PUBLISHED
Reserved Date
December 22, 2021
Published Date
December 22, 2021
Last Updated
August 04, 2024
Vendor
n/a
Product
n/a
Description
FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.

CVSS Scores

CVSS v3.1

9.8 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

7.5

Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Exploit Status

Exploited in the Wild
Yes (2021-12-22 18:25:54 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2021-12-22 18:25:54 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel