Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
BID:50990
Info
Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
| Bugtraq ID: | 50990 |
| Class: | Design Error |
| CVE: |
CVE-2011-4597 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2011 12:00AM |
| Updated: | Apr 13 2015 09:47PM |
| Credit: | Terry Wilson |
| Vulnerable: |
Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Asterisk Asterisk 1.8.4 2 Asterisk Asterisk 1.8.4 1 Asterisk Asterisk 1.8.2 4 Asterisk Asterisk 1.8.1 Asterisk Asterisk 1.8 Asterisk Asterisk 1.6.2 16.2 Asterisk Asterisk 1.6.2 .5 Asterisk Asterisk 1.6.2 Asterisk Asterisk 1.6.1 22 Asterisk Asterisk 1.6.1 11 Asterisk Asterisk 1.6.1 0-rc2 Asterisk Asterisk 1.6.1 0-rc1 Asterisk Asterisk 1.6.1 .9 Asterisk Asterisk 1.6.1 .6 Asterisk Asterisk 1.6.1 .5 Asterisk Asterisk 1.6.1 .17 Asterisk Asterisk 1.6.1 Asterisk Asterisk 1.6 beta6 Asterisk Asterisk 1.6 6 Asterisk Asterisk 1.6 19 Asterisk Asterisk 1.6 .8 Asterisk Asterisk 1.6 .25 Asterisk Asterisk 1.6 .17 Asterisk Asterisk 1.4.39 2 Asterisk Asterisk 1.4.27 1 Asterisk Asterisk 1.4.26 .3 Asterisk Asterisk 1.4.26 Asterisk Asterisk 1.4.24 .1 Asterisk Asterisk 1.4.24 Asterisk Asterisk 1.4.23 .2 Asterisk Asterisk 1.4.23 .1 Asterisk Asterisk 1.4.23 Asterisk Asterisk 1.4.22 Asterisk Asterisk 1.4.19 .1 Asterisk Asterisk 1.4.19 -rc3 Asterisk Asterisk 1.4.19 Asterisk Asterisk 1.4.18 Asterisk Asterisk 1.4.17 Asterisk Asterisk 1.4.16 Asterisk Asterisk 1.4.15 Asterisk Asterisk 1.4.14 Asterisk Asterisk 1.4.13 Asterisk Asterisk 1.4.12 Asterisk Asterisk 1.4.11 Asterisk Asterisk 1.4.10 Asterisk Asterisk 1.4.9 Asterisk Asterisk 1.4.8 Asterisk Asterisk 1.4.7 Asterisk Asterisk 1.4.6 Asterisk Asterisk 1.4.5 Asterisk Asterisk 1.4.4 Asterisk Asterisk 1.4.3 Asterisk Asterisk 1.4.2 Asterisk Asterisk 1.4.1 Asterisk Asterisk 10.0 Asterisk Asterisk 1.8.7.2 Asterisk Asterisk 1.8.7.1 Asterisk Asterisk 1.8.4.4 Asterisk Asterisk 1.8.4.3 Asterisk Asterisk 1.8.3.3 Asterisk Asterisk 1.8.3.1 Asterisk Asterisk 1.8.2.1 Asterisk Asterisk 1.8.1.2 Asterisk Asterisk 1.8 Asterisk Asterisk 1.6.2.21 Asterisk Asterisk 1.6.2.20 Asterisk Asterisk 1.6.2.2 Asterisk Asterisk 1.6.2.18.2 Asterisk Asterisk 1.6.2.18.1 Asterisk Asterisk 1.6.2.17.3 Asterisk Asterisk 1.6.2.17.1 Asterisk Asterisk 1.6.2.16.1 Asterisk Asterisk 1.6.2.15.1 Asterisk Asterisk 1.6.1.8 Asterisk Asterisk 1.6.1.7 Asterisk Asterisk 1.6.1.25 Asterisk Asterisk 1.6.1.23 Asterisk Asterisk 1.6.1.21 Asterisk Asterisk 1.6.1.14 Asterisk Asterisk 1.6.0.3 Asterisk Asterisk 1.6.0.22 Asterisk Asterisk 1.6.0.15 Asterisk Asterisk 1.6.0.14 Asterisk Asterisk 1.6 Asterisk Asterisk 1.4.41.2 Asterisk Asterisk 1.4.41.1 Asterisk Asterisk 1.4.39.1 Asterisk Asterisk 1.4.38.1 Asterisk Asterisk 1.4.26.2 Asterisk Asterisk 1.4.26.1 Asterisk Asterisk 1.4.22.1 Asterisk Asterisk 1.4.21.2 Asterisk Asterisk 1.4.18.1 Asterisk Asterisk 1.4 revision 95946 Asterisk Asterisk 1.4 Beta Asterisk Asterisk 1.4.40.1 |
| Not Vulnerable: | |
Discussion
Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
Asterisk is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in brute-force attacks.
All Asterisk versions are vulnerable.
Asterisk is prone to a user-enumeration weakness.
An attacker may leverage this issue to harvest valid usernames, which may aid in brute-force attacks.
All Asterisk versions are vulnerable.
Exploit / POC
Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Asterisk SIP Endpoints NAT Settings User Enumeration Weakness
References:
References:
- Asterisk Homepage (Asterisk)
- AST-2011-013: Possible remote enumeration of SIP endpoints with differing NAT se (Full Disclosure)