Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Asterisk Open Source 安全漏洞
Vulnerability Description
Asterisk Open Source 1.4.43之前的1.4.x版本, 1.6.2.21之前的1.6.x版本以及1.8.7.2之前的1.8.x版本中存在漏洞,SIP over UDP implementation 根据是否存在SIP用户名,使用不同的端口号响应无效的请求。远程攻击者可利用该漏洞通过一系列请求枚举用户名。
CVSS Information
N/A
Vulnerability Type
N/A