Summary
The commercial sangomartapi module (Sangoma Connect “RT API”) exposes insufficiently protected services on port 6082 that can be exploited by unauthenticated attackers in a special sequence to bypass login requirements and ultimately execute commands on the host as the asterisk user.
Provider Urgency is set to Amber. But this gets Red if you have a misconfigured firewall. Please take action now.
Common Vulnerabilities and Exposures (CVE)
Requested
GitHub Security Advisory (GHSA)
GHSA-h9vq-j62m-6m73
Provider Urgency (choice of: Not Defined, Clear, Green, Amber, or Red)
A - Amber
Link to Published GHSA with More Details
Highlights
for most but
for those with insufficient firewalls.