VYPR
Medium severity4.9NVD Advisory· Published Dec 5, 2022· Updated Jun 17, 2026

CVE-2022-42706

CVE-2022-42706

Description

An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Freepbx/Asterisk4 versions
    cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*range: >=16.0.0,<16.29.1
    • cpe:2.3:a:sangoma:asterisk:20.0.0:*:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: <=16.28, 17, <=18.14, <=19.6, <=18.9-cert1
  • cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*range: <18.9
    • cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.