HIGH

CVE-2020-7351

CVSS v3

8.8

HIGH

EPSS Score

67.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.

Technical details

Published
5/1/2020

Frequently asked questions

What is CVE-2020-7351?

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.

Is CVE-2020-7351 actively exploited?

Active exploitation of CVE-2020-7351 has not been confirmed. The EPSS score is 67.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-7351?

CVE-2020-7351 has a CVSS v3 base score of 8.8 (HIGH severity).

Is CVE-2020-7351 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.