CVE-2024-53566

An issue in the action_listcategories() function of Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 allows attackers to execute a path traversal.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sangoma:asterisk:22.0.0:-:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:pre1:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:rc2:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

History

17 Jun 2026, 08:08

Type Values Removed Values Added
References () https://gist.github.com/hyp164D1/e7c0f44ffb38c00320aa1a6d98bee616 - () https://gist.github.com/hyp164D1/e7c0f44ffb38c00320aa1a6d98bee616 - Third Party Advisory
References () https://github.com/asterisk/asterisk/blob/22/main/manager.c#L2556 - () https://github.com/asterisk/asterisk/blob/22/main/manager.c#L2556 - Product
References () https://lists.debian.org/debian-lts-announce/2025/02/msg00003.html - () https://lists.debian.org/debian-lts-announce/2025/02/msg00003.html - Mailing List, Third Party Advisory
First Time Sangoma
Debian
Debian debian Linux
Sangoma asterisk
CPE cpe:2.3:a:sangoma:asterisk:22.0.0:-:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:rc2:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:pre1:*:*:*:*:*:*
cpe:2.3:a:sangoma:asterisk:22.0.0:rc1:*:*:*:*:*:*

06 Feb 2025, 02:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/02/msg00003.html -
Summary
  • (es) Un problema en la función action_listcategories() de Sangoma Asterisk v22/22.0.0/22.0.0-rc1/22.0.0-rc2/22.0.0-pre1 permite a los atacantes ejecutar un path traversal.

02 Dec 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-02 18:15

Updated : 2026-06-17 08:08


NVD link : CVE-2024-53566

Mitre link : CVE-2024-53566

CVE.ORG link : CVE-2024-53566


JSON object : View

Products Affected

sangoma

  • asterisk

debian

  • debian_linux
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')