PT-2011-4013 · Digium · Asterisk Open Source
Published
2011-07-06
·
Updated
2017-08-29
·
CVE-2011-2666
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Asterisk Open Source versions 1.4.x through 1.4.41.2
Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2
Description
The default configuration of the SIP channel driver in Asterisk Open Source does not enable the alwaysauthreject option. This allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames.
Recommendations
For Asterisk Open Source versions 1.4.x through 1.4.41.2, enable the alwaysauthreject option to prevent account name enumeration.
For Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2, enable the alwaysauthreject option to prevent account name enumeration.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Asterisk Open Source