CVE-2019-12147
Estado: ModificadaCrítica (9.8)—
The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.63%
- Percentil entre todas las CVEs puntuadas: 85
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-88
Referencias
- http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.html
- http://seclists.org/fulldisclosure/2019/Oct/40
- https://blog.appsecco.com
- http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.html
- http://seclists.org/fulldisclosure/2019/Oct/40
- https://blog.appsecco.com
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-12147",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2019-10-22T16:15:10.707",
"references": [
{
"url": "http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2019/Oct/40",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://blog.appsecco.com",
"tags": [
"Not Applicable"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/154914/Sangoma-SBC-2.3.23-119-GA-Unauthenticated-User-Creation.html",
"tags": [
"Exploit",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2019/Oct/40",
"tags": [
"Exploit",
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blog.appsecco.com",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-88"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the username field. Upon successful exploitation, a remote unauthenticated user can create a local system user with sudo privileges, and use that user to login to the system (either via the web interface or via SSH) to achieve complete compromise of the device. This affects /var/webconfig/gui/Webconfig.inc.php and /usr/local/sng/bin/sng-user-mgmt."
},
{
"lang": "es",
"value": "La interfaz web GA de Sangoma Session Border Controller (SBC) versión 2.3.23-119, es vulnerable a una Inyección de Argumentos mediante caracteres especiales en el campo username. Tras una explotación con éxito, un usuario no autenticado remoto puede crear un usuario del sistema local con privilegios de sudo, y usar ese usuario para iniciar sesión en el sistema (bien sea por medio de la interfaz web o mediante SSH) para lograr un compromiso completo del dispositivo. Esto afecta a los archivos /var/webconfig/gui/Webconfig.inc.php y /usr/local/sng/bin/sng-user-mgmt."
}
],
"lastModified": "2026-06-17T02:14:08.753",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:sangoma:session_border_controller_firmware:2.3.23-119-ga:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4FFF84F0-DC4E-4584-867B-A3A6D777F325"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:sangoma:session_border_controller:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DD535F8D-3066-4D4F-A3B3-C547D19D2A2D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}