AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2012-2414

MEDIUM · CVSS 6.5 EPSS 2.72%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2012-04-30 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2012-2414
Severity
MEDIUM
CVSS
6.5
EPSS
2.72%

Original Filing — NVD Description

main/manager.c in the Manager Interface in Asterisk Open Source 1.6.2.x before 1.6.2.24, 1.8.x before 1.8.11.1, and 10.x before 10.3.1 and Asterisk Business Edition C.3.x before C.3.7.4 does not properly enforce System class authorization requirements, which allows remote authenticated users to execute arbitrary commands via (1) the originate action in the MixMonitor application, (2) the SHELL and EVAL functions in the GetVar manager action, or (3) the SHELL and EVAL functions in the Status manager action.