PT-2011-4013 · Digium · Asterisk Open Source

Publicado

2011-07-06

·

Atualizado

2017-08-29

·

CVE-2011-2666

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asterisk Open Source versions 1.4.x through 1.4.41.2 Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2
Description The default configuration of the SIP channel driver in Asterisk Open Source does not enable the alwaysauthreject option. This allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames.
Recommendations For Asterisk Open Source versions 1.4.x through 1.4.41.2, enable the alwaysauthreject option to prevent account name enumeration. For Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2, enable the alwaysauthreject option to prevent account name enumeration.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2666

Produtos afetados

Asterisk Open Source