cli_permissions.conf: deny option does not work for disallowing shell commands
Published May 22, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.26%
Description
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Affected products
-
Affected
- < 18.9-cert14
- ≥ 18.10, < 18.26.2
- ≥ 20.0, < 20.7-cert5
- ≥ 20.8, < 20.14.1
- ≥ 21.0, < 21.9.1
- ≥ 22.0, < 22.4.1
Configuration 1
Configuration 2
- < 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 18.9
- 20.7
- 20.7
- 20.7
- 20.7
- 20.7
- 20.7
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28125 Advisory
- https://github.com/asterisk/asterisk/security/advisories/GHSA-c7p6-7mvq-8jq2 x_refsource_CONFIRMExploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/06/msg00003.html
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-28125 | Advisory | |
| https://github.com/asterisk/asterisk/security/advisories/GHSA-c7p6-7mvq-8jq2 | x_refsource_CONFIRMExploitVendor Advisory | |
| https://lists.debian.org/debian-lts-announce/2025/06/msg00003.html |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data