5

CVE-2009-0041

IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0.3-rc2; Business Edition A.x.x, B.x.x before B.2.5.7, C.1.x.x before C.1.10.4, and C.2.x.x before C.2.1.2.1; and s800i 1.2.x before 1.3.0 responds differently to a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AsteriskAsterisk Business Edition Version <= b.2.5.2
AsteriskAsterisk Business Edition Updatebeta8 Version <= c.1.0
AsteriskAsterisk Business Edition Versionb.1.3.2
AsteriskAsterisk Business Edition Versionb.1.3.3
AsteriskAsterisk Business Edition Versionb.2.2.0
AsteriskAsterisk Business Edition Versionb.2.2.1
AsteriskAsterisk Business Edition Versionb.2.3.1
AsteriskAsterisk Business Edition Versionb.2.3.2
AsteriskAsterisk Business Edition Versionb.2.3.3
AsteriskAsterisk Business Edition Versionb.2.3.4
AsteriskAsterisk Business Edition Versionb.2.3.5
AsteriskAsterisk Business Edition Versionb.2.3.6
AsteriskAsterisk Business Edition Versionb.2.5.0
AsteriskAsterisk Business Edition Versionb.2.5.1
AsteriskAsterisk Business Edition Versionb.2.5.3
AsteriskAsterisk Business Edition Versionc.1.0 Updatebeta7
AsteriskOpen Source Version <= 1.2.30.4
AsteriskOpen Source Updaterc3 Version <= 1.4.23
AsteriskOpen Source Updaterc1 Version <= 1.6.0.3
AsteriskOpen Source Version1.2.0
AsteriskOpen Source Version1.2.0 Updatebeta1
AsteriskOpen Source Version1.2.0 Updatebeta2
AsteriskOpen Source Version1.2.0 Updaterc1
AsteriskOpen Source Version1.2.0 Updaterc2
AsteriskOpen Source Version1.2.0beta1
AsteriskOpen Source Version1.2.0beta2
AsteriskOpen Source Version1.2.1
AsteriskOpen Source Version1.2.2
AsteriskOpen Source Version1.2.2 Updatenetsec
AsteriskOpen Source Version1.2.3
AsteriskOpen Source Version1.2.3 Updatenetsec
AsteriskOpen Source Version1.2.10
AsteriskOpen Source Version1.2.10 Updatenetsec
AsteriskOpen Source Version1.2.11
AsteriskOpen Source Version1.2.11 Updatenetsec
AsteriskOpen Source Version1.2.12
AsteriskOpen Source Version1.2.12 Updatenetsec
AsteriskOpen Source Version1.2.12.1
AsteriskOpen Source Version1.2.12.1 Updatenetsec
AsteriskOpen Source Version1.2.13
AsteriskOpen Source Version1.2.13 Updatenetsec
AsteriskOpen Source Version1.2.14
AsteriskOpen Source Version1.2.14 Updatenetsec
AsteriskOpen Source Version1.2.15
AsteriskOpen Source Version1.2.15 Updatenetsec
AsteriskOpen Source Version1.2.16
AsteriskOpen Source Version1.2.16 Updatenetsec
AsteriskOpen Source Version1.2.17
AsteriskOpen Source Version1.2.17 Updatenetsec
AsteriskOpen Source Version1.2.18
AsteriskOpen Source Version1.2.18 Updatenetsec
AsteriskOpen Source Version1.2.19
AsteriskOpen Source Version1.2.19 Updatenetsec
AsteriskOpen Source Version1.2.20
AsteriskOpen Source Version1.2.20 Updatenetsec
AsteriskOpen Source Version1.2.21
AsteriskOpen Source Version1.2.21 Updatenetsec
AsteriskOpen Source Version1.2.21.1
AsteriskOpen Source Version1.2.21.1 Updatenetsec
AsteriskOpen Source Version1.2.22
AsteriskOpen Source Version1.2.22 Updatenetsec
AsteriskOpen Source Version1.2.23
AsteriskOpen Source Version1.2.23 Updatenetsec
AsteriskOpen Source Version1.2.24
AsteriskOpen Source Version1.2.24 Updatenetsec
AsteriskOpen Source Version1.2.25
AsteriskOpen Source Version1.2.25 Updatenetsec
AsteriskOpen Source Version1.2.26
AsteriskOpen Source Version1.2.26 Updatenetsec
AsteriskOpen Source Version1.2.26.1
AsteriskOpen Source Version1.2.26.1 Updatenetsec
AsteriskOpen Source Version1.2.26.2
AsteriskOpen Source Version1.2.26.2 Updatenetsec
AsteriskOpen Source Version1.2.27
AsteriskOpen Source Version1.2.28
AsteriskOpen Source Version1.2.29
AsteriskOpen Source Version1.2.30
AsteriskOpen Source Version1.2.30.2
AsteriskOpen Source Version1.2.30.3
AsteriskOpen Source Version1.4.0
AsteriskOpen Source Version1.4.0 Updatebeta2
AsteriskOpen Source Version1.4.0 Updatebeta3
AsteriskOpen Source Version1.4.0 Updatebeta4
AsteriskOpen Source Version1.4.1
AsteriskOpen Source Version1.4.2
AsteriskOpen Source Version1.4.3
AsteriskOpen Source Version1.4.4
AsteriskOpen Source Version1.4.5
AsteriskOpen Source Version1.4.6
AsteriskOpen Source Version1.4.7
AsteriskOpen Source Version1.4.7.1
AsteriskOpen Source Version1.4.8
AsteriskOpen Source Version1.4.9
AsteriskOpen Source Version1.4.10
AsteriskOpen Source Version1.4.10.1
AsteriskOpen Source Version1.4.11
AsteriskOpen Source Version1.4.12
AsteriskOpen Source Version1.4.12.1
AsteriskOpen Source Version1.4.13
AsteriskOpen Source Version1.4.14
AsteriskOpen Source Version1.4.15
AsteriskOpen Source Version1.4.16
AsteriskOpen Source Version1.4.16.1
AsteriskOpen Source Version1.4.16.2
AsteriskOpen Source Version1.4.17
AsteriskOpen Source Version1.4.18
AsteriskOpen Source Version1.4.18.1
AsteriskOpen Source Version1.4.19
AsteriskOpen Source Version1.4.19 Updaterc1
AsteriskOpen Source Version1.4.19 Updaterc2
AsteriskOpen Source Version1.4.19 Updaterc3
AsteriskOpen Source Version1.4.19 Updaterc4
AsteriskOpen Source Version1.4.19.1
AsteriskOpen Source Version1.4.19.2
AsteriskOpen Source Version1.4.20
AsteriskOpen Source Version1.4.20 Updaterc1
AsteriskOpen Source Version1.4.20 Updaterc2
AsteriskOpen Source Version1.4.20 Updaterc3
AsteriskOpen Source Version1.4.21
AsteriskOpen Source Version1.4.21 Updaterc1
AsteriskOpen Source Version1.4.21 Updaterc2
AsteriskOpen Source Version1.4.21.1
AsteriskOpen Source Version1.4.21.2
AsteriskOpen Source Version1.4.22
AsteriskOpen Source Version1.4.22 Updaterc3
AsteriskOpen Source Version1.4.22 Updaterc4
AsteriskOpen Source Version1.4.22.1
AsteriskOpen Source Version1.4.22.2
AsteriskOpen Source Version1.4.23
AsteriskOpen Source Version1.4.23 Updaterc1
AsteriskOpen Source Version1.4.23 Updaterc2
AsteriskOpen Source Version1.4_revision_95946
AsteriskOpen Source Version1.4beta
AsteriskOpen Source Version1.6.0 Updatebeta1
AsteriskOpen Source Version1.6.0 Updatebeta2
AsteriskOpen Source Version1.6.0 Updatebeta3
AsteriskOpen Source Version1.6.0 Updatebeta4
AsteriskOpen Source Version1.6.0 Updatebeta5
AsteriskOpen Source Version1.6.0 Updatebeta7
AsteriskOpen Source Version1.6.0 Updatebeta7.1
AsteriskOpen Source Version1.6.0 Updatebeta8
AsteriskOpen Source Version1.6.0 Updatebeta9
AsteriskOpen Source Version1.6.0 Updaterc4
AsteriskOpen Source Version1.6.0 Updaterc5
AsteriskOpen Source Version1.6.0 Updaterc6
AsteriskOpen Source Version1.6.0.1
AsteriskOpen Source Version1.6.0.2
AsteriskOpen Source Version1.6.0.3
AsteriskS800i Appliance Version1.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.69% 0.693
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.