PoC Index

CVE-2011-4597

MEDIUM 5.0EPSS 3.2%

The SIP over UDP implementation in Asterisk Open Source 1.4.x before 1.4.43, 1.6.x before 1.6.2.21, and 1.8.x before 1.8.7.2 uses different port numbers for responses to invalid requests depending on whether a SIP username exists, which allows remote attackers to enumerate usernames via a series of requests.

CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
3.16% chance of exploitation in the next 30 days, 87th percentile
Published
2011-12-15
Updated
2024-08-07

Proof-of-concept exploits (1)

References

Related