PT-2011-4013 · Digium · Asterisk Open Source

Published

2011-07-06

·

Updated

2017-08-29

·

CVE-2011-2666

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asterisk Open Source versions 1.4.x through 1.4.41.2 Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2
Description The default configuration of the SIP channel driver in Asterisk Open Source does not enable the alwaysauthreject option. This allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames.
Recommendations For Asterisk Open Source versions 1.4.x through 1.4.41.2, enable the alwaysauthreject option to prevent account name enumeration. For Asterisk Open Source versions 1.6.2.x through 1.6.2.18.2, enable the alwaysauthreject option to prevent account name enumeration.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2666

Affected Products

Asterisk Open Source