Unrated severityNVD Advisory· Published Nov 24, 2014· Updated Jun 17, 2026
CVE-2014-8418
CVE-2014-8418
Description
The DB dialplan function in Asterisk Open Source 1.8.x before 1.8.32, 11.x before 11.1.4.1, 12.x before 12.7.1, and 13.x before 13.0.1 and Certified Asterisk 1.8 before 1.8.28-cert8 and 11.6 before 11.6-cert8 allows remote authenticated users to gain privileges via a call from an external protocol, as demonstrated by the AMI protocol.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:digium:certified_asterisk:11.6.0:-:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:digium:certified_asterisk:11.6.0:-:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert1:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert2:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert3:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert4:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert5:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert6:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:11.6:cert7:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:*:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert1:*:*:lts:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert1-rc1:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert2:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert2:*:*:lts:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert3:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert4:*:*:*:*:*:*
- cpe:2.3:a:digium:certified_asterisk:1.8.28:cert5:*:*:*:*:*:*
- Range: 1.8 <1.8.28-cert8, 11.6 <11.6-cert8
- Range: 1.8.x <1.8.32, 11.x <11.1.4.1, 12.x <12.7.1, 13.x <13.0.1
Patches
Vulnerability mechanics
References
1- downloads.asterisk.org/pub/security/AST-2014-018.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.