← Back

CVE-2008-1390

nvd nist
Published: Mar 24, 2008Modified: Apr 23, 2026

JSON object

Loading...
9.3
Vector
AV:N/AC:M/Au:N/C:C/I:C/A:C
Exploitability: 8.6 / Impact: 10.0
Source: NVD

Description

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

Affected (40)

5 products
Asterisk
Asterisk Appliance Developer Kit
Asterisk Business Edition
Asterisknow
S800i
Configuration A
40 vulnerable
Vulnerable SoftwareAffected Versions
Asterisk
Version 1.4.10
Version 1.4.11
Version 1.4.12
Version 1.4.13
Version 1.4.14
Version 1.4.15
Version 1.4.16
Version 1.4.17
Version 1.4.18.1
Version 1.4.1
Version 1.4.2
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4_beta
Version 1.4_revision_95946
Version 1.6
Asterisk
Version 0.2
Version 0.3
Version 0.4
Version 0.5
Version 0.6
Version 0.7
Version 0.8
Version 1.4
Asterisk
Version c.1.0-beta7
Version c.1.0-beta8
Asterisk
Version 1.0
Version beta_5
Version beta_6
Version beta_7
Asterisk
Version 1.0.1
Version 1.0.2
Version 1.0.3
Version 1.0
Version 1.1.0

Related CWEs

References (20)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.