Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-1390

Опубликовано: 24 мар. 2008
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:asterisk:asterisk:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.9:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.11:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.14:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.15:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.16:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.17:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4.18.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4_beta:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.4_revision_95946:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk:1.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:0.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_appliance_developer_kit:1.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:c.1.0-beta7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:c.1.0-beta8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisknow:1.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisknow:beta_5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisknow:beta_6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisknow:beta_7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:s800i:1.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:s800i:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:s800i:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:s800i:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:s800i:1.1.0:*:*:*:*:*:*:*

EPSS

Процентиль: 85%
0.02654
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-255

Связанные уязвимости

ubuntu
больше 17 лет назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

debian
больше 17 лет назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.1 ...

github
больше 3 лет назад

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

EPSS

Процентиль: 85%
0.02654
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-255