Vulnerability Details CVE-2025-47780
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.7%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-47780
-
cpe:2.3:a:sangoma:asterisk:-
-
cpe:2.3:a:sangoma:asterisk:1.6.1
-
cpe:2.3:a:sangoma:asterisk:1.6.1.4
-
cpe:2.3:a:sangoma:asterisk:1.6.1.8
-
cpe:2.3:a:sangoma:asterisk:13.0.0
-
cpe:2.3:a:sangoma:asterisk:13.1.0
-
cpe:2.3:a:sangoma:asterisk:13.10.0
-
cpe:2.3:a:sangoma:asterisk:13.11.0
-
cpe:2.3:a:sangoma:asterisk:13.12.0
-
cpe:2.3:a:sangoma:asterisk:13.12.1
-
cpe:2.3:a:sangoma:asterisk:13.12.2
-
cpe:2.3:a:sangoma:asterisk:13.13.0
-
cpe:2.3:a:sangoma:asterisk:13.14.0
-
cpe:2.3:a:sangoma:asterisk:13.15.0
-
cpe:2.3:a:sangoma:asterisk:13.2.0
-
cpe:2.3:a:sangoma:asterisk:13.3.0
-
cpe:2.3:a:sangoma:asterisk:13.37.1
-
cpe:2.3:a:sangoma:asterisk:13.4.0
-
cpe:2.3:a:sangoma:asterisk:13.5.0
-
cpe:2.3:a:sangoma:asterisk:13.6.0
-
cpe:2.3:a:sangoma:asterisk:13.7.0
-
cpe:2.3:a:sangoma:asterisk:13.8.0
-
cpe:2.3:a:sangoma:asterisk:13.8.1
-
cpe:2.3:a:sangoma:asterisk:13.8.2
-
cpe:2.3:a:sangoma:asterisk:13.9.0
-
cpe:2.3:a:sangoma:asterisk:14.0.0
-
cpe:2.3:a:sangoma:asterisk:14.1.0
-
cpe:2.3:a:sangoma:asterisk:14.2.0
-
cpe:2.3:a:sangoma:asterisk:14.2.1
-
cpe:2.3:a:sangoma:asterisk:14.3.0
-
cpe:2.3:a:sangoma:asterisk:14.4.0
-
cpe:2.3:a:sangoma:asterisk:15.0.0
-
cpe:2.3:a:sangoma:asterisk:15.1.0
-
cpe:2.3:a:sangoma:asterisk:15.1.2
-
cpe:2.3:a:sangoma:asterisk:15.1.4
-
cpe:2.3:a:sangoma:asterisk:15.1.5
-
cpe:2.3:a:sangoma:asterisk:15.2.0
-
cpe:2.3:a:sangoma:asterisk:15.2.1
-
cpe:2.3:a:sangoma:asterisk:15.2.2
-
cpe:2.3:a:sangoma:asterisk:15.3.0
-
cpe:2.3:a:sangoma:asterisk:15.4.0
-
cpe:2.3:a:sangoma:asterisk:15.4.1
-
cpe:2.3:a:sangoma:asterisk:16.0.0
-
cpe:2.3:a:sangoma:asterisk:16.10.0
-
cpe:2.3:a:sangoma:asterisk:16.11.0
-
cpe:2.3:a:sangoma:asterisk:16.12.0
-
cpe:2.3:a:sangoma:asterisk:16.14.0
-
cpe:2.3:a:sangoma:asterisk:16.14.1
-
cpe:2.3:a:sangoma:asterisk:16.15.0
-
cpe:2.3:a:sangoma:asterisk:16.16.0
-
cpe:2.3:a:sangoma:asterisk:16.16.1
-
cpe:2.3:a:sangoma:asterisk:16.5.0
-
cpe:2.3:a:sangoma:asterisk:16.6.0
-
cpe:2.3:a:sangoma:asterisk:16.7.0
-
cpe:2.3:a:sangoma:asterisk:16.8.0
-
cpe:2.3:a:sangoma:asterisk:16.9.0
-
cpe:2.3:a:sangoma:asterisk:17.0.0
-
cpe:2.3:a:sangoma:asterisk:17.1.0
-
cpe:2.3:a:sangoma:asterisk:17.2.0
-
cpe:2.3:a:sangoma:asterisk:17.3.0
-
cpe:2.3:a:sangoma:asterisk:17.4.0
-
cpe:2.3:a:sangoma:asterisk:17.5.0
-
cpe:2.3:a:sangoma:asterisk:17.6.0
-
cpe:2.3:a:sangoma:asterisk:17.7.0
-
cpe:2.3:a:sangoma:asterisk:17.8.0
-
cpe:2.3:a:sangoma:asterisk:17.8.1
-
cpe:2.3:a:sangoma:asterisk:17.9.0
-
cpe:2.3:a:sangoma:asterisk:17.9.1
-
cpe:2.3:a:sangoma:asterisk:17.9.2
-
cpe:2.3:a:sangoma:asterisk:18.0.0
-
cpe:2.3:a:sangoma:asterisk:18.0.1
-
cpe:2.3:a:sangoma:asterisk:18.1.0
-
cpe:2.3:a:sangoma:asterisk:18.1.1
-
cpe:2.3:a:sangoma:asterisk:18.10.0
-
cpe:2.3:a:sangoma:asterisk:18.10.1
-
cpe:2.3:a:sangoma:asterisk:18.11.0
-
cpe:2.3:a:sangoma:asterisk:18.11.1
-
cpe:2.3:a:sangoma:asterisk:18.11.2
-
cpe:2.3:a:sangoma:asterisk:18.11.3
-
cpe:2.3:a:sangoma:asterisk:18.12.0
-
cpe:2.3:a:sangoma:asterisk:18.12.1
-
cpe:2.3:a:sangoma:asterisk:18.13.0
-
cpe:2.3:a:sangoma:asterisk:18.14.0
-
cpe:2.3:a:sangoma:asterisk:18.15.0
-
cpe:2.3:a:sangoma:asterisk:18.15.1
-
cpe:2.3:a:sangoma:asterisk:18.16.0
-
cpe:2.3:a:sangoma:asterisk:18.17.0
-
cpe:2.3:a:sangoma:asterisk:18.17.1
-
cpe:2.3:a:sangoma:asterisk:18.18.0
-
cpe:2.3:a:sangoma:asterisk:18.18.1
-
cpe:2.3:a:sangoma:asterisk:18.19.0
-
cpe:2.3:a:sangoma:asterisk:18.2.0
-
cpe:2.3:a:sangoma:asterisk:18.2.1
-
cpe:2.3:a:sangoma:asterisk:18.2.2
-
cpe:2.3:a:sangoma:asterisk:18.20.0
-
cpe:2.3:a:sangoma:asterisk:18.20.1
-
cpe:2.3:a:sangoma:asterisk:18.20.2
-
cpe:2.3:a:sangoma:asterisk:18.21.0
-
cpe:2.3:a:sangoma:asterisk:18.22.0
-
cpe:2.3:a:sangoma:asterisk:18.23.0
-
cpe:2.3:a:sangoma:asterisk:18.23.1
-
cpe:2.3:a:sangoma:asterisk:18.24.0
-
cpe:2.3:a:sangoma:asterisk:18.24.1
-
cpe:2.3:a:sangoma:asterisk:18.24.2
-
cpe:2.3:a:sangoma:asterisk:18.24.3
-
cpe:2.3:a:sangoma:asterisk:18.25.0
-
cpe:2.3:a:sangoma:asterisk:18.26.0
-
cpe:2.3:a:sangoma:asterisk:18.26.1
-
cpe:2.3:a:sangoma:asterisk:18.3.0
-
cpe:2.3:a:sangoma:asterisk:18.4.0
-
cpe:2.3:a:sangoma:asterisk:18.5.0
-
cpe:2.3:a:sangoma:asterisk:18.5.1
-
cpe:2.3:a:sangoma:asterisk:18.6.0
-
cpe:2.3:a:sangoma:asterisk:18.7.0
-
cpe:2.3:a:sangoma:asterisk:18.7.1
-
cpe:2.3:a:sangoma:asterisk:18.8.0
-
cpe:2.3:a:sangoma:asterisk:18.9.0
-
cpe:2.3:a:sangoma:asterisk:20.0.0
-
cpe:2.3:a:sangoma:asterisk:20.0.1
-
cpe:2.3:a:sangoma:asterisk:20.1.0
-
cpe:2.3:a:sangoma:asterisk:20.10.0
-
cpe:2.3:a:sangoma:asterisk:20.11.0
-
cpe:2.3:a:sangoma:asterisk:20.11.1
-
cpe:2.3:a:sangoma:asterisk:20.12.0
-
cpe:2.3:a:sangoma:asterisk:20.13.0
-
cpe:2.3:a:sangoma:asterisk:20.14.0
-
cpe:2.3:a:sangoma:asterisk:20.2.0
-
cpe:2.3:a:sangoma:asterisk:20.2.1
-
cpe:2.3:a:sangoma:asterisk:20.3.0
-
cpe:2.3:a:sangoma:asterisk:20.3.1
-
cpe:2.3:a:sangoma:asterisk:20.4.0
-
cpe:2.3:a:sangoma:asterisk:20.5.0
-
cpe:2.3:a:sangoma:asterisk:20.5.1
-
cpe:2.3:a:sangoma:asterisk:20.5.2
-
cpe:2.3:a:sangoma:asterisk:20.6.0
-
cpe:2.3:a:sangoma:asterisk:20.7.0
-
cpe:2.3:a:sangoma:asterisk:20.8.0
-
cpe:2.3:a:sangoma:asterisk:20.8.1
-
cpe:2.3:a:sangoma:asterisk:20.9.0
-
cpe:2.3:a:sangoma:asterisk:20.9.1
-
cpe:2.3:a:sangoma:asterisk:20.9.2
-
cpe:2.3:a:sangoma:asterisk:20.9.3
-
cpe:2.3:a:sangoma:asterisk:21.0.0
-
cpe:2.3:a:sangoma:asterisk:21.0.1
-
cpe:2.3:a:sangoma:asterisk:21.0.2
-
cpe:2.3:a:sangoma:asterisk:21.1.0
-
cpe:2.3:a:sangoma:asterisk:21.2.0
-
cpe:2.3:a:sangoma:asterisk:21.3.0
-
cpe:2.3:a:sangoma:asterisk:21.3.1
-
cpe:2.3:a:sangoma:asterisk:21.4.0
-
cpe:2.3:a:sangoma:asterisk:21.4.1
-
cpe:2.3:a:sangoma:asterisk:21.4.2
-
cpe:2.3:a:sangoma:asterisk:21.4.3
-
cpe:2.3:a:sangoma:asterisk:21.5.0
-
cpe:2.3:a:sangoma:asterisk:21.6.0
-
cpe:2.3:a:sangoma:asterisk:21.6.1
-
cpe:2.3:a:sangoma:asterisk:21.7.0
-
cpe:2.3:a:sangoma:asterisk:21.8.0
-
cpe:2.3:a:sangoma:asterisk:21.9.0
-
cpe:2.3:a:sangoma:asterisk:22.0.0
-
cpe:2.3:a:sangoma:asterisk:22.1.0
-
cpe:2.3:a:sangoma:asterisk:22.1.1
-
cpe:2.3:a:sangoma:asterisk:22.2.0
-
cpe:2.3:a:sangoma:asterisk:22.3.0
-
cpe:2.3:a:sangoma:asterisk:22.4.0
-
cpe:2.3:a:sangoma:certified_asterisk:-
-
cpe:2.3:a:sangoma:certified_asterisk:13.13.0
-
cpe:2.3:a:sangoma:certified_asterisk:16.8
-
cpe:2.3:a:sangoma:certified_asterisk:16.8.0
-
cpe:2.3:a:sangoma:certified_asterisk:18.9
-
cpe:2.3:a:sangoma:certified_asterisk:20.7