4.3

CVE-2007-6430

Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AsteriskAsterisk Business Edition Versionb.1.3.2
AsteriskAsterisk Business Edition Versionb.1.3.3
AsteriskAsterisk Business Edition Versionb.2.2.0
AsteriskAsterisk Business Edition Versionb.2.2.1
AsteriskAsterisk Business Edition Versionb.2.3.1
AsteriskAsterisk Business Edition Versionb.2.3.2
AsteriskAsterisk Business Edition Versionb.2.3.3
AsteriskAsterisk Business Edition Versionb.2.3.4
AsteriskAsterisk Business Edition Versionc.1.0beta7
AsteriskOpen Source Version1.2.0beta1
AsteriskOpen Source Version1.2.0beta2
AsteriskOpen Source Version1.2.5
AsteriskOpen Source Version1.2.6
AsteriskOpen Source Version1.2.7
AsteriskOpen Source Version1.2.8
AsteriskOpen Source Version1.2.9
AsteriskOpen Source Version1.2.10
AsteriskOpen Source Version1.2.11
AsteriskOpen Source Version1.2.13
AsteriskOpen Source Version1.2.14
AsteriskOpen Source Version1.2.15
AsteriskOpen Source Version1.2.16
AsteriskOpen Source Version1.2.17
AsteriskOpen Source Version1.2.18
AsteriskOpen Source Version1.2.19
AsteriskOpen Source Version1.2.21
AsteriskOpen Source Version1.2.22
AsteriskOpen Source Version1.2.23
AsteriskOpen Source Version1.2.24
AsteriskOpen Source Version1.2.25
AsteriskOpen Source Version1.4.1
AsteriskOpen Source Version1.4.2
AsteriskOpen Source Version1.4.3
AsteriskOpen Source Version1.4.4
AsteriskOpen Source Version1.4.5
AsteriskOpen Source Version1.4.6
AsteriskOpen Source Version1.4.7
AsteriskOpen Source Version1.4.8
AsteriskOpen Source Version1.4.9
AsteriskOpen Source Version1.4.10
AsteriskOpen Source Version1.4.11
AsteriskOpen Source Version1.4.12
AsteriskOpen Source Version1.4.13
AsteriskOpen Source Version1.4.14
AsteriskOpen Source Version1.4.15
AsteriskOpen Source Version1.4beta
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.666
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.