Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2011-2536 | First vendor Publication | 2011-07-06 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:P/I:N/A:N) | |||
---|---|---|---|
Cvss Base Score | 5 | Attack Range | Network |
Cvss Impact Score | 2.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
chan_sip.c in the SIP channel driver in Asterisk Open Source 1.4.x before 1.4.41.2, 1.6.2.x before 1.6.2.18.2, and 1.8.x before 1.8.4.4, and Asterisk Business Edition C.3.x before C.3.7.3, disregards the alwaysauthreject option and generates different responses for invalid SIP requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2536 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-200 | Information Exposure |
CPE : Common Platform Enumeration
OpenVAS Exploits
Date | Description |
---|---|
2012-02-12 | Name : Gentoo Security Advisory GLSA 201110-21 (Asterisk) File : nvt/glsa_201110_21.nasl |
2011-08-03 | Name : FreeBSD Ports: asterisk14 File : nvt/freebsd_asterisk142.nasl |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
73257 | Asterisk SIP Multiple Message Response Username Enumeration |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2011-11-22 | Name : A telephony application running on the remote host is affected by an informat... File : asterisk_ast_2011_011.nasl - Type : ACT_GATHER_INFO |
2011-10-25 | Name : The remote Gentoo host is missing one or more security-related patches. File : gentoo_GLSA-201110-21.nasl - Type : ACT_GATHER_INFO |
2011-06-27 | Name : The remote FreeBSD host is missing one or more security-related updates. File : freebsd_pkg_40544e8c9f7b11e09bec6c626dd55a41.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Source | Url |
---|
Alert History
Date | Informations |
---|---|
2024-11-28 23:04:44 |
|
2024-11-28 12:26:09 |
|
2021-05-04 12:14:44 |
|
2021-04-22 01:16:03 |
|
2020-05-23 00:28:57 |
|
2016-04-26 20:52:04 |
|
2014-02-17 11:03:23 |
|
2013-05-10 23:03:19 |
|