🟠 Authenticated RCE in FindMeFollowMe function of Sangoma Connect

Summary

The commercial sangomartapi module (Sangoma Connect “RT API”) exposes insufficiently protected services on port 6082 that can be exploited by low-privileged attackers to execute commands on the host as the asterisk user.

Authentication with a known username is required.

Provider Urgency is set to Amber. Please take action.

Common Vulnerabilities and Exposures (CVE)

Requested

GitHub Security Advisory (GHSA)

GHSA-2f5p-xvrc-j2wf

Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)

A - Amber

Link to Published GHSA with More Details

Highlights

:orange_circle: