Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade asterisk | Jul 30, 2024 | Dec 20, 2007 |
| Gentoo Linux | — | Upgrade net-misc/asterisk. | Oct 30, 2017 | Dec 19, 2007 |
| Suse | — | Upgrade asterisk-spandspUpgrade asteriskUpgrade asterisk-zaptelUpgrade asterisk-pgsqlUpgrade asterisk-alsaUpgrade suse-releaseUpgrade asterisk-odbc | Feb 17, 2015 | Dec 19, 2007 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub