Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Digium Asterisk SIP信道驱动程序默认配置用户名枚举漏洞
Vulnerability Description
Digium Asterisk是美国Digium公司的一套开源的电话交换机(PBX)系统软件。该软件支持语音信箱、多方语音会议、交互式语音应答(IVR)等。 Asterisk Open Source 1.4.x至1.4.41.2版本和1.6.2.x至1.6.2.18.2版本的SIP信道驱动程序的默认配置没有启用alwaysauthreject选项。远程攻击者可以通过发起一系列无效SIP请求并观察不同用户名响应中的差异枚举账户名。
CVSS Information
N/A
Vulnerability Type
N/A