CVE-2022-26651SQL Injection in Asterisk

CWE-89SQL Injection7 documents5 sources
Severity
9.8CRITICALNVD
OSV5.5
EPSS
0.7%
top 28.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15
Latest updateSep 26

Description

An issue was discovered in Asterisk through 19.x and Certified Asterisk through 16.8-cert13. The func_odbc module provides possibly inadequate escaping functionality for backslash characters in SQL queries, resulting in user-provided data creating a broken SQL query or possibly a SQL injection. This is fixed in 16.25.2, 18.11.2, and 19.3.2, and 16.8-cert14.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages5 packages

NVDdigium/asterisk16.0.016.25.2+2
debiandebian/asterisk< asterisk 1:16.28.0~dfsg-0+deb11u1 (bullseye)
Debiandigium/asterisk< 1:16.28.0~dfsg-0+deb11u1
Ubuntulinux/linux_kernel< 4.4.0-259.293

Also affects: Debian Linux 10.0, 11.0

🔴Vulnerability Details

3
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2024-09-26
GHSA
GHSA-6pcv-f66p-pqqj: An issue was discovered in Asterisk through 192022-04-16
OSV
CVE-2022-26651: An issue was discovered in Asterisk through 192022-04-15

📋Vendor Advisories

1
Debian
CVE-2022-26651: asterisk - An issue was discovered in Asterisk through 19.x and Certified Asterisk through ...2022

💬Community

2
Bugzilla
CVE-2022-26498 CVE-2022-26499 CVE-2022-26651 asterisk: multiple vulnerabilities [epel-all]2022-04-18
Bugzilla
CVE-2022-26498 CVE-2022-26499 CVE-2022-26651 asterisk: multiple vulnerabilities [fedora-all]2022-04-18
CVE-2022-26651 — SQL Injection in Digium Asterisk | cvebase