// For flags

CVE-2007-6430

 

Severity Score

4.3
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.

Asterisk Open Source 1.2.x anterior a 1.2.26 y 1.4.x anterior a 1.4.16, y Business Edition B.x.x anterior a B.2.3.6 y C.x.x anterior a C.1.0-beta8, cuando usa registros basados en base de datos (en tiempo real o "realtime") y autenticación basada en anfitrión (host-based), no comprueba la dirección IP cuando el nombre de usuario es correcto y no hay contraseña, lo cual permite a atacantes remotos evitar la autenticación usando un nombre de usuario válido.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-12-18 CVE Reserved
  • 2007-12-19 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.1.3.2
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.1.3.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.1.3.3
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.1.3.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.2.0
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.2.0"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.2.1
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.2.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.1
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.2
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.3
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
b.2.3.4
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "b.2.3.4"
-
Affected
Asterisk
Search vendor "Asterisk"
Asterisk Business Edition
Search vendor "Asterisk" for product "Asterisk Business Edition"
c.1.0beta7
Search vendor "Asterisk" for product "Asterisk Business Edition" and version "c.1.0beta7"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.0beta1
Search vendor "Asterisk" for product "Open Source" and version "1.2.0beta1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.0beta2
Search vendor "Asterisk" for product "Open Source" and version "1.2.0beta2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.5
Search vendor "Asterisk" for product "Open Source" and version "1.2.5"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.6
Search vendor "Asterisk" for product "Open Source" and version "1.2.6"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.7
Search vendor "Asterisk" for product "Open Source" and version "1.2.7"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.8
Search vendor "Asterisk" for product "Open Source" and version "1.2.8"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.9
Search vendor "Asterisk" for product "Open Source" and version "1.2.9"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.10
Search vendor "Asterisk" for product "Open Source" and version "1.2.10"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.11
Search vendor "Asterisk" for product "Open Source" and version "1.2.11"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.13
Search vendor "Asterisk" for product "Open Source" and version "1.2.13"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.14
Search vendor "Asterisk" for product "Open Source" and version "1.2.14"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.15
Search vendor "Asterisk" for product "Open Source" and version "1.2.15"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.16
Search vendor "Asterisk" for product "Open Source" and version "1.2.16"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.17
Search vendor "Asterisk" for product "Open Source" and version "1.2.17"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.18
Search vendor "Asterisk" for product "Open Source" and version "1.2.18"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.19
Search vendor "Asterisk" for product "Open Source" and version "1.2.19"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.21
Search vendor "Asterisk" for product "Open Source" and version "1.2.21"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.22
Search vendor "Asterisk" for product "Open Source" and version "1.2.22"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.23
Search vendor "Asterisk" for product "Open Source" and version "1.2.23"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.24
Search vendor "Asterisk" for product "Open Source" and version "1.2.24"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.2.25
Search vendor "Asterisk" for product "Open Source" and version "1.2.25"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.1
Search vendor "Asterisk" for product "Open Source" and version "1.4.1"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.2
Search vendor "Asterisk" for product "Open Source" and version "1.4.2"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.3
Search vendor "Asterisk" for product "Open Source" and version "1.4.3"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.4
Search vendor "Asterisk" for product "Open Source" and version "1.4.4"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.5
Search vendor "Asterisk" for product "Open Source" and version "1.4.5"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.6
Search vendor "Asterisk" for product "Open Source" and version "1.4.6"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.7
Search vendor "Asterisk" for product "Open Source" and version "1.4.7"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.8
Search vendor "Asterisk" for product "Open Source" and version "1.4.8"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.9
Search vendor "Asterisk" for product "Open Source" and version "1.4.9"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.10
Search vendor "Asterisk" for product "Open Source" and version "1.4.10"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.11
Search vendor "Asterisk" for product "Open Source" and version "1.4.11"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.12
Search vendor "Asterisk" for product "Open Source" and version "1.4.12"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.13
Search vendor "Asterisk" for product "Open Source" and version "1.4.13"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.14
Search vendor "Asterisk" for product "Open Source" and version "1.4.14"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4.15
Search vendor "Asterisk" for product "Open Source" and version "1.4.15"
-
Affected
Asterisk
Search vendor "Asterisk"
Open Source
Search vendor "Asterisk" for product "Open Source"
1.4beta
Search vendor "Asterisk" for product "Open Source" and version "1.4beta"
-
Affected