4.3
CVSSv2

CVE-2007-6430

Published: 20/12/2007 Updated: 15/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Asterisk Open Source 1.2.x prior to 1.2.26 and 1.4.x prior to 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote malicious users to bypass authentication using a valid username.

Vulnerable Product Search on Vulmon Subscribe to Product

asterisk asterisk business edition b.2.3.3

asterisk asterisk business edition b.2.3.4

asterisk asterisk business edition c.1.0beta7

asterisk open source 1.2.15

asterisk open source 1.2.16

asterisk open source 1.2.24

asterisk open source 1.2.25

asterisk open source 1.4.11

asterisk open source 1.4.12

asterisk open source 1.4.5

asterisk open source 1.4.6

asterisk asterisk business edition b.2.2.0

asterisk asterisk business edition b.2.2.1

asterisk open source 1.2.10

asterisk open source 1.2.11

asterisk open source 1.2.19

asterisk open source 1.2.21

asterisk open source 1.2.7

asterisk open source 1.2.8

asterisk open source 1.4.15

asterisk open source 1.4.2

asterisk open source 1.4.9

asterisk open source 1.4beta

asterisk asterisk business edition b.2.3.1

asterisk asterisk business edition b.2.3.2

asterisk open source 1.2.13

asterisk open source 1.2.14

asterisk open source 1.2.22

asterisk open source 1.2.23

asterisk open source 1.2.9

asterisk open source 1.4.1

asterisk open source 1.4.10

asterisk open source 1.4.3

asterisk open source 1.4.4

asterisk asterisk business edition b.1.3.2

asterisk asterisk business edition b.1.3.3

asterisk open source 1.2.0beta1

asterisk open source 1.2.0beta2

asterisk open source 1.2.17

asterisk open source 1.2.18

asterisk open source 1.2.5

asterisk open source 1.2.6

asterisk open source 1.4.13

asterisk open source 1.4.14

asterisk open source 1.4.7

asterisk open source 1.4.8

Vendor Advisories

Debian Bug report logs - #457063 asterisk: CVE-2007-6430 remote unauthenticated sessions Package: asterisk; Maintainer for asterisk is Debian VoIP Team <pkg-voip-maintainers@listsaliothdebianorg>; Source for asterisk is src:asterisk (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Wed, 19 Dec ...
Several remote vulnerabilities have been discovered in Asterisk, a free software PBX and telephony toolkit The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-6430 Tilghman Lesher discovered that database-based registrations are insufficiently validated This only affects setups, which are conf ...