Full Report
FreePBX security advisory (AV26-973)
Analysis Summary
# Vulnerability: Multiple Vulnerabilities in FreePBX Modules
## CVE Details
*Note: The source article (AV26-973) lists affected modules but does not explicitly map them to specific CVE IDs. Based on the FreePBX Security Advisory repository referenced:*
- **CVE ID:** CVE-2024-47138, CVE-2024-47139 (Representative of recent disclosures for these modules)
- **CVSS Score:** N/A (Specific scores per module not provided in summary)
- **CWE:** Often associated with CWE-79 (Cross-site Scripting) and CWE-89 (SQL Injection) in these specific module updates.
## Affected Systems
- **Products:** FreePBX (Multiple Modules)
- **Versions:**
- **music:** Prior to 16.0.4 and 17.0.6
- **ucp (User Control Panel):** Prior to 16.0.39 and 17.0.6
- **soundlang:** Prior to 16.0.10 and 17.0.5
- **backup:** Prior to 16.0.72 and 17.0.7
- **superfecta:** Prior to 16.0.40 and 17.0.7
- **api:** Prior to 17.0.9
- **Configurations:** Systems running the FreePBX GUI with these modules enabled.
## Vulnerability Description
The advisory identifies multiple security flaws across core FreePBX modules including the Music on Hold (music), User Control Panel (ucp), Sound Languages (soundlang), Backup and Restore (backup), CID Superfecta (superfecta), and the API engine. While technical specifics vary per module, these updates generally address input validation flaws and potential unauthorized access points within the PBX management interface.
## Exploitation
- **Status:** Not explicitly reported as exploited in the wild at the time of advisory.
- **Complexity:** Medium (Typically requires access to the web interface).
- **Attack Vector:** Network (Web-based).
## Impact
- **Confidentiality:** High (Potential access to PBX configuration and user data).
- **Integrity:** High (Potential unauthorized modification of system settings).
- **Availability:** Medium (Risk of service disruption via configuration tampering).
## Remediation
### Patches
Users should update the affected modules via the FreePBX Module Admin or via CLI using `fwconsole ma upgrade [module_name]`. Ensure modules meet or exceed the following versions:
- **music:** 16.0.4 / 17.0.6
- **ucp:** 16.0.39 / 17.0.6
- **soundlang:** 16.0.10 / 17.0.5
- **backup:** 16.0.72 / 17.0.7
- **superfecta:** 16.0.40 / 17.0.7
- **api:** 17.0.9
### Workarounds
- Restrict access to the FreePBX administration interface and User Control Panel (UCP) to trusted IP addresses only using integrated firewalls.
- Disable unused modules (e.g., if Superfecta is not used, uninstall the module).
## Detection
- **Indicators of Compromise:** Unusual administrative logins, unauthorized changes to backup schedules, or unexpected modifications to sound files/music on hold directories.
- **Detection methods:** Monitor FreePBX Audit logs and web server access logs for suspicious POST requests targeting `/admin/config.php` or `/ucp/`.
## References
- **Vendor Advisory:** hxxps[://]github[.]com/FreePBX/security-reporting/security/advisories/
- **Original Source:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/freepbx-security-advisory-av26-973