Lucene search

K
cveMitreCVE-2008-1390
HistoryMar 24, 2008 - 5:44 p.m.

CVE-2008-1390

2008-03-2417:44:00
CWE-255
mitre
web.nvd.nist.gov
42
asteriskgui
http server
vulnerability
remote attackers
hijack
manager sessions
id values
cve-2008-1390
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.038

Percentile

92.0%

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

Affected configurations

Nvd
Node
asteriskasteriskMatch1.4.1
OR
asteriskasteriskMatch1.4.2
OR
asteriskasteriskMatch1.4.3
OR
asteriskasteriskMatch1.4.4
OR
asteriskasteriskMatch1.4.5
OR
asteriskasteriskMatch1.4.6
OR
asteriskasteriskMatch1.4.7
OR
asteriskasteriskMatch1.4.8
OR
asteriskasteriskMatch1.4.9
OR
asteriskasteriskMatch1.4.10
OR
asteriskasteriskMatch1.4.11
OR
asteriskasteriskMatch1.4.12
OR
asteriskasteriskMatch1.4.13
OR
asteriskasteriskMatch1.4.14
OR
asteriskasteriskMatch1.4.15
OR
asteriskasteriskMatch1.4.16
OR
asteriskasteriskMatch1.4.17
OR
asteriskasteriskMatch1.4.18.1
OR
asteriskasteriskMatch1.4_beta
OR
asteriskasteriskMatch1.4_revision_95946
OR
asteriskasteriskMatch1.6
OR
asteriskasterisk_appliance_developer_kitMatch0.2
OR
asteriskasterisk_appliance_developer_kitMatch0.3
OR
asteriskasterisk_appliance_developer_kitMatch0.4
OR
asteriskasterisk_appliance_developer_kitMatch0.5
OR
asteriskasterisk_appliance_developer_kitMatch0.6
OR
asteriskasterisk_appliance_developer_kitMatch0.7
OR
asteriskasterisk_appliance_developer_kitMatch0.8
OR
asteriskasterisk_appliance_developer_kitMatch1.4
OR
asteriskasterisk_business_editionMatchc.1.0-beta7
OR
asteriskasterisk_business_editionMatchc.1.0-beta8
OR
asteriskasterisknowMatch1.0
OR
asteriskasterisknowMatchbeta_5
OR
asteriskasterisknowMatchbeta_6
OR
asteriskasterisknowMatchbeta_7
OR
asterisks800iMatch1.0
OR
asterisks800iMatch1.0.1
OR
asterisks800iMatch1.0.2
OR
asterisks800iMatch1.0.3
OR
asterisks800iMatch1.1.0
VendorProductVersionCPE
asteriskasterisk1.4.1cpe:2.3:a:asterisk:asterisk:1.4.1:*:*:*:*:*:*:*
asteriskasterisk1.4.2cpe:2.3:a:asterisk:asterisk:1.4.2:*:*:*:*:*:*:*
asteriskasterisk1.4.3cpe:2.3:a:asterisk:asterisk:1.4.3:*:*:*:*:*:*:*
asteriskasterisk1.4.4cpe:2.3:a:asterisk:asterisk:1.4.4:*:*:*:*:*:*:*
asteriskasterisk1.4.5cpe:2.3:a:asterisk:asterisk:1.4.5:*:*:*:*:*:*:*
asteriskasterisk1.4.6cpe:2.3:a:asterisk:asterisk:1.4.6:*:*:*:*:*:*:*
asteriskasterisk1.4.7cpe:2.3:a:asterisk:asterisk:1.4.7:*:*:*:*:*:*:*
asteriskasterisk1.4.8cpe:2.3:a:asterisk:asterisk:1.4.8:*:*:*:*:*:*:*
asteriskasterisk1.4.9cpe:2.3:a:asterisk:asterisk:1.4.9:*:*:*:*:*:*:*
asteriskasterisk1.4.10cpe:2.3:a:asterisk:asterisk:1.4.10:*:*:*:*:*:*:*
Rows per page:
1-10 of 401

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

6.3

Confidence

Low

EPSS

0.038

Percentile

92.0%