Back to Database
Status published
High
CVE-2015-1590
The kamcmd administrative utility and default configuration in kamailio before...
Vulnerability Description
The kamcmd administrative utility and default configuration in kamailio before 4.3.0 use /tmp/kamailio_ctl.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2015-1590
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.openwall.com/lists/oss-security/2015/02/12/7
- https://github.com/kamailio/kamailio/issues/48
- https://github.com/kamailio/kamailio/blob/4.3.0/ChangeLog#L2038
- https://github.com/kamailio/kamailio/commit/06177b12936146d48378cc5f6c6e1b157ebd519b
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=775681
More from kamailio
View All →CVE-2020-28361
Kamailio before 5.4.0, as used in Sip Express Router (SER)...
Medium
5.4
CVE-2020-27507
The Kamailio SIP before 5.5.0 server mishandles INVITE requests with...
Unknown
0
CVE-2018-8828
A Buffer Overflow issue was discovered in Kamailio before 4.4.7,...
Critical
9.8
CVE-2015-1591
The kamailio build in kamailio before 4.2.0-2 process allows local...
High
7.8
CVE-2013-7426
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1....
Critical
9.8
Affected Vendor
kamailio
View all reports →Affected Software
kamailio
Vulnerable Versions:
0
Timeline
Official Publish:
September 7th, 2017
Last Modified:
August 6th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.