« Volver al listado

CVE-2026-49841

Estado: AnalizadaCrítica (9.8)—

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs. This issue has been patched in version 1.11.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector CVSS AV:N/AC:L/PR:N sin interacción del usuario indica explotación remota sin autenticación (T1190). Desbordamiento de búfer en heap permite ejecutar código arbitrario (T1059) y potencialmente escalar privilegios (T1068). Ocurre antes de autenticación HTTP.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-49841",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-49841",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "signalwire",
          "product": "freeswitch",
          "versions": [
            {
              "status": "affected",
              "version": "< 1.11.1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-09T17:17:47.870",
  "references": [
    {
      "url": "https://github.com/signalwire/freeswitch/releases/tag/v1.11.1",
      "tags": [
        "Release Notes"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/signalwire/freeswitch/security/advisories/GHSA-wfrq-qvg2-f88f",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-122"
        },
        {
          "lang": "en",
          "value": "CWE-131"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs. This issue has been patched in version 1.11.1."
    },
    {
      "lang": "es",
      "value": "FreeSWITCH es una Pila de Telecomunicaciones Definida por Software que permite la transformación digital de conmutadores de telecomunicaciones propietarios a una implementación de software que se ejecuta en cualquier hardware comercial. Antes de la versión 1.11.1, el gestor de solicitudes HTTP mod_verto asigna un búfer fijo de 2 MiB para un cuerpo POST application/x-www-form-urlencoded, pero acepta Content-Length de hasta poco menos de 10 MiB. El bucle de lectura del cuerpo está limitado por Content-Length en lugar de por el tamaño del búfer, produciendo un desbordamiento de montículo controlado por el atacante de hasta ~8 MiB -- antes de que se ejecute la comprobación de autenticación básica HTTP. Este problema ha sido parcheado en la versión 1.11.1."
    }
  ],
  "lastModified": "2026-07-23T08:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freeswitch:freeswitch:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8AED0D0-D5A1-4AA1-9CAE-13830B74CAC5",
              "versionEndExcluding": "1.11.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}