CVE-2011-2666: Medium severity asterisk vulnerability
The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2666?
CVE-2011-2666 has been assigned a medium severity rating due to its ability to allow account enumeration through invalid SIP requests.
How do I fix CVE-2011-2666?
To mitigate CVE-2011-2666, enable the alwaysauthreject option in the SIP channel driver configuration.
Which versions of Asterisk are affected by CVE-2011-2666?
CVE-2011-2666 affects Asterisk versions 1.4.x up to 1.4.41.2 and 1.6.2.x up to 1.6.2.18.2.
What kind of attack can exploit CVE-2011-2666?
CVE-2011-2666 can be exploited by remote attackers to enumerate account names through crafted SIP requests.
Is there a patch available for CVE-2011-2666?
Yes, patches are available and can be implemented by configuring the SIP channel driver appropriately.