« Volver al listado

CVE-2009-1803

Estado: ModificadaMedia (5)—

FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-1803",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2009-05-28T14:30:00.390",
  "references": [
    {
      "url": "http://freepbx.org/trac/ticket/3660",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/54263",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34857",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://freepbx.org/trac/ticket/3660",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34772",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/54263",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34857",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "FreePBX 2.5.1, and other 2.4.x, 2.5.x, and pre-release 2.6.x versions, generates different error messages for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames."
    },
    {
      "lang": "es",
      "value": "FreePBX v2.5.1, v2.4.x, v2.5.x, y pre-release v2.6.x, genera distintos errores tras intentos de login fallidos dependiendo de si la cuenta de usuario existe o no, lo que permite a atacantes remotos listar nombres de usuarios váalidos."
    }
  ],
  "lastModified": "2026-06-16T23:08:05.253",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "455E97D6-B069-49D6-B510-3D4112A9E1B3"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.0_beta1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF1E1278-3114-4BD1-B589-30B5313C9502"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.0_beta2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32D216B0-31D6-4288-8773-FB2438944492"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A09E3F0-E1A6-4CC4-8134-89DF5DB6EA3B"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5B2C1156-93B6-4D71-8D9C-ED6FC6C0AE74"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0_beta1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "11ACC1C9-A2C3-41CA-B608-C474B642A380"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D8A021AB-A142-4DAD-9EB0-2352C625D8CC"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.0rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C0B173F-2161-4E40-A712-90DA6B997820"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "613A39A4-976E-4535-9408-533F957F7F87"
            },
            {
              "criteria": "cpe:2.3:a:freepbx:freepbx:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5B657C6-A2DF-432A-9F46-1157C630CB20"
            },
            {
              "criteria": "cpe:2.3:a:sangoma:freepbx:2.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9734B50E-BEA8-41DF-835F-7B15A9BB31E8"
            },
            {
              "criteria": "cpe:2.3:a:sangoma:freepbx:2.5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9645D4F-BB03-49AD-AE79-6FE990BF18FE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}