ID

VAR-202509-3117


CVE

CVE-2025-1131


DESCRIPTION

A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions. Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.

Trust: 1.0

sources: NVD: CVE-2025-1131

AFFECTED PRODUCTS

vendor:sangomamodel:asteriskscope:ltversion:20.15.1

Trust: 1.0

vendor:sangomamodel:asteriskscope:gteversion:20.0.0

Trust: 1.0

vendor:sangomamodel:certified asteriskscope:eqversion:20.7

Trust: 1.0

vendor:sangomamodel:asteriskscope:ltversion:18.26.3

Trust: 1.0

vendor:sangomamodel:asteriskscope:gteversion:22.0.0

Trust: 1.0

vendor:sangomamodel:asteriskscope:ltversion:22.5.1

Trust: 1.0

vendor:sangomamodel:certified asteriskscope:eqversion:18.9

Trust: 1.0

vendor:sangomamodel:asteriskscope:gteversion:21.0.0

Trust: 1.0

vendor:sangomamodel:asteriskscope:ltversion:21.10.1

Trust: 1.0

sources: NVD: CVE-2025-1131

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2025-1131
value: HIGH

Trust: 1.0

b7efe717-a805-47cf-8e9a-921fca0ce0ce: CVE-2025-1131
value: HIGH

Trust: 1.0

nvd@nist.gov: CVE-2025-1131
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: NVD: CVE-2025-1131 // NVD: CVE-2025-1131

PROBLEMTYPE DATA

problemtype:CWE-427

Trust: 1.0

sources: NVD: CVE-2025-1131

EXTERNAL IDS

db:NVDid:CVE-2025-1131

Trust: 1.0

sources: NVD: CVE-2025-1131

REFERENCES

url:https://github.com/asterisk/asterisk/security/advisories/ghsa-v9q8-9j8m-5xwp

Trust: 1.0

sources: NVD: CVE-2025-1131

SOURCES

db:NVDid:CVE-2025-1131

LAST UPDATE DATE

2025-10-09T23:23:47.193000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2025-1131date:2025-10-08T20:35:00.300

SOURCES RELEASE DATE

db:NVDid:CVE-2025-1131date:2025-09-23T05:15:35.603