Critical severity9.8NVD Advisory· Published Feb 5, 2025· Updated Jun 17, 2026
CVE-2024-57520
CVE-2024-57520
Description
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. NOTE: this is disputed by the Supplier because the impact is limited to creating empty files outside of the Asterisk product directory (aka directory traversal) and the attack can only be performed by a privileged user who has the ability to manage the configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- gist.github.com/hyp164D1/ae76ab25acfbe263b2ed7b24b6e5c621nvdThird Party Advisory
- github.com/asterisk/asterisk/issues/1122nvd
News mentions
0No linked articles in our index yet.