PT-2011-4013 · Digium · Asterisk Open Source
Publicado
2011-07-06
·
Atualizado
2017-08-29
·
CVE-2011-2666
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asterisk Open Source versions 1.4.x through 1.4.41.2
Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2
Description
The default configuration of the SIP channel driver in Asterisk Open Source does not enable the alwaysauthreject option. This allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames.
Recommendations
For Asterisk Open Source versions 1.4.x through 1.4.41.2, enable the alwaysauthreject option to prevent account name enumeration.
For Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2, enable the alwaysauthreject option to prevent account name enumeration.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Asterisk Open Source