High severity8.1NVD Advisory· Published Apr 26, 2023· Updated Jun 17, 2026
CVE-2023-26567
CVE-2023-26567
Description
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:sangoma:freepbx_linux_7:1805:*:*:*:*:*:*:*+ 13 more
- cpe:2.3:a:sangoma:freepbx_linux_7:1805:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:1904:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:1910:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2002:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2008:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2011:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2104:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2105:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2109:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2112:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2201:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2202:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2203:*:*:*:*:*:*:*
- cpe:2.3:a:sangoma:freepbx_linux_7:2302:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- qsecure.com.cy/resources/advisories/sangoma-freepbx-linux-insecure-permissionsnvdThird Party Advisory
- www.freepbx.orgnvdProduct
- www.sangoma.com/products/open-source/nvdProduct
News mentions
0No linked articles in our index yet.