Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2011-2666
Description:The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2011-2666
XForce ISS Database: asterisk-sip-channel-info-disclosure(68472)
https://exchange.xforce.ibmcloud.com/vulnerabilities/68472




© 1998-2025 E-Soft Inc. All rights reserved.