« Volver al listado

CVE-2008-3903

Estado: ModificadaBaja (3.5)—

Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled, generates different responses depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3903",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-09-04T19:41:00.000",
  "references": [
    {
      "url": "http://downloads.asterisk.org/pub/security/AST-2009-003.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://misel.com/?p=52",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34982",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/37677",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200905-01.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1952",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34353",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0933",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45059",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://downloads.asterisk.org/pub/security/AST-2009-003.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://misel.com/?p=52",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34982",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/37677",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-200905-01.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2009/dsa-1952",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34353",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0933",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45059",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Asterisk Open Source 1.2.x before 1.2.32, 1.4.x before 1.4.24.1, and 1.6.0.x before 1.6.0.8; Asterisk Business Edition A.x.x, B.x.x before B.2.5.8, C.1.x.x before C.1.10.5, and C.2.x.x before C.2.3.3; s800i 1.3.x before 1.3.0.2; and Trixbox PBX 2.6.1, when Digest authentication and authalwaysreject are enabled, generates different responses depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames."
    },
    {
      "lang": "es",
      "value": "Asterisk PBX 1.2 a la v.1.6 y Trixbox PBX 2.6.1, cuando se ejecuta con autenticación Digest y authalwaysreject activadas, genera diferentes respuestas dependiendo de si un nombre de usuario SIP es válido o no, lo que permite a atacantes remotos el listar nombres de usuario válidos."
    }
  ],
  "lastModified": "2026-06-16T22:56:46.497",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:asterisk:p_b_x:1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7CE2414C-4DA8-42BB-BF9A-21850C5D60D3"
            },
            {
              "criteria": "cpe:2.3:a:asterisk:p_b_x:1.2.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "90F13AAE-CB97-4EF1-8407-760FB219EAD9"
            },
            {
              "criteria": "cpe:2.3:a:asterisk:p_b_x:1.4.21.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9A77D2E4-2C33-4208-A760-D102B91E511A"
            },
            {
              "criteria": "cpe:2.3:a:asterisk:p_b_x:1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "15BBAB9C-20A4-48CE-B0EF-5D99E87E20F7"
            },
            {
              "criteria": "cpe:2.3:a:trixbox:pbx:2.6.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C75A09A7-25CF-4D58-8517-6FB311DA1F1B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Additional details can be found here: http://www.voipsa.org/pipermail/voipsec_voipsa.org/2006-May/001628.html",
  "sourceIdentifier": "cve@mitre.org"
}