Vulnerability Description
The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Asterisk | Asterisk | 1.4.1 |
| Asterisk | Asterisk Appliance Developer Kit | 0.2 |
| Asterisk | Asterisk Business Edition | c.1.0-beta7 |
| Asterisk | Asterisknow | 1.0 |
| Asterisk | S800I | 1.0 |
Related Weaknesses (CWE)
References
- http://downloads.digium.com/pub/security/AST-2008-005.html
- http://secunia.com/advisories/29449Vendor Advisory
- http://secunia.com/advisories/29470
- http://securityreason.com/securityalert/3764
- http://www.securityfocus.com/archive/1/489819/100/0/threaded
- http://www.securityfocus.com/bid/28316
- http://www.securitytracker.com/id?1019679
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41304
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00438.html
- https://www.redhat.com/archives/fedora-package-announce/2008-March/msg00514.html
- http://downloads.digium.com/pub/security/AST-2008-005.html
- http://secunia.com/advisories/29449Vendor Advisory
- http://secunia.com/advisories/29470
- http://securityreason.com/securityalert/3764
- http://www.securityfocus.com/archive/1/489819/100/0/threaded
FAQ
What is CVE-2008-1390?
CVE-2008-1390 is a vulnerability with a CVSS score of 9.3 (HIGH). The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before ...
How severe is CVE-2008-1390?
CVE-2008-1390 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-1390?
Check the references section above for vendor advisories and patch information. Affected products include: Asterisk Asterisk, Asterisk Asterisk Appliance Developer Kit, Asterisk Asterisk Business Edition, Asterisk Asterisknow, Asterisk S800I.