Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16,...
Vulnerability Description
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-6430
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/28149
- http://secunia.com/advisories/29782
- http://security.gentoo.org/glsa/glsa-200804-13.xml
- http://secunia.com/advisories/29242
- http://www.securityfocus.com/archive/1/485287/100/0/threaded
- http://lists.opensuse.org/opensuse-security-announce/2008-03/msg00001.html
- http://www.vupen.com/english/advisories/2007/4260
- http://www.debian.org/security/2008/dsa-1525
- http://securityreason.com/securityalert/3467
- http://www.osvdb.org/39519
- http://www.securitytracker.com/id?1019110
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39124
- http://secunia.com/advisories/29456
- http://www.securityfocus.com/bid/26928
- http://downloads.digium.com/pub/security/AST-2007-027.html
More from asterisk
View All →Affected Vendor
asterisk
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.