Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2009-0041

Опубликовано: 14 янв. 2009
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Комментарий

Vendor Advisory: http://downloads.digium.com/pub/security/AST-2009-001.html

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:asterisk:asterisk_business_edition:*:*:*:*:*:*:*:*
Версия до b.2.5.2 (включая)
cpe:2.3:a:asterisk:asterisk_business_edition:*:beta8:*:*:*:*:*:*
Версия до c.1.0 (включая)
cpe:2.3:a:asterisk:asterisk_business_edition:a:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.1.3.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.3.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:b.2.5.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:asterisk_business_edition:c.1.0:beta7:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:*:*:*:*:*:*:*:*
Версия до 1.2.30.4 (включая)
cpe:2.3:a:asterisk:open_source:*:rc3:*:*:*:*:*:*
Версия до 1.4.23 (включая)
cpe:2.3:a:asterisk:open_source:*:rc1:*:*:*:*:*:*
Версия до 1.6.0.3 (включая)
cpe:2.3:a:asterisk:open_source:1.2.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0:beta1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0beta1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.0beta2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.2:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.3:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.10:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.11:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.11:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.12:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.12.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.12.1:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.13:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.14:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.14:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.15:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.15:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.16:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.16:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.17:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.17:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.18:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.18:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.19:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.19:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.20:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.20:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.21:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.21:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.21.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.21.1:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.22:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.22:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.23:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.23:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.24:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.24:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.25:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.25:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26.1:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.26.2:netsec:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.27:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.28:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.29:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.30:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.30.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.2.30.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.0:beta3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.0:beta4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.3:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.4:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.5:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.6:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.7:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.8:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.9:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.10:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.10.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.11:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.12:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.12.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.13:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.14:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.15:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.16:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.16.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.16.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.17:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.18:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.18.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.19.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.20:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.20:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.20:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.20:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.21:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.21:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.21:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.21.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.21.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.22:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.22:rc3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.22:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.22.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.22.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.23:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.23:rc1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4.23:rc2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4_revision_95946:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.4beta:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta2:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta3:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta7:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta7.1:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta8:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:beta9:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:rc4:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:rc5:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0:rc6:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:asterisk:open_source:1.6.0.3:*:*:*:*:*:*:*
cpe:2.3:h:asterisk:s800i_appliance:1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 74%
0.0086
Низкий

5 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

ubuntu
почти 17 лет назад

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

redhat
почти 17 лет назад

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

debian
почти 17 лет назад

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23- ...

github
больше 3 лет назад

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

EPSS

Процентиль: 74%
0.0086
Низкий

5 Medium

CVSS2

Дефекты

CWE-200