Vulnerability Details CVE-2011-2666
The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, which allows remote attackers to enumerate account names by making a series of invalid SIP requests and observing the differences in the responses for different usernames, a different vulnerability than CVE-2011-2536.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.0%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2011-2666
-
cpe:2.3:a:digium:asterisk:1.4.0
-
cpe:2.3:a:digium:asterisk:1.4.1
-
cpe:2.3:a:digium:asterisk:1.4.10
-
cpe:2.3:a:digium:asterisk:1.4.10.1
-
cpe:2.3:a:digium:asterisk:1.4.11
-
cpe:2.3:a:digium:asterisk:1.4.12
-
cpe:2.3:a:digium:asterisk:1.4.12.1
-
cpe:2.3:a:digium:asterisk:1.4.13
-
cpe:2.3:a:digium:asterisk:1.4.14
-
cpe:2.3:a:digium:asterisk:1.4.15
-
cpe:2.3:a:digium:asterisk:1.4.16
-
cpe:2.3:a:digium:asterisk:1.4.16.1
-
cpe:2.3:a:digium:asterisk:1.4.16.2
-
cpe:2.3:a:digium:asterisk:1.4.17
-
cpe:2.3:a:digium:asterisk:1.4.18
-
cpe:2.3:a:digium:asterisk:1.4.19
-
cpe:2.3:a:digium:asterisk:1.4.19.1
-
cpe:2.3:a:digium:asterisk:1.4.19.2
-
cpe:2.3:a:digium:asterisk:1.4.2
-
cpe:2.3:a:digium:asterisk:1.4.20
-
cpe:2.3:a:digium:asterisk:1.4.20.1
-
cpe:2.3:a:digium:asterisk:1.4.21
-
cpe:2.3:a:digium:asterisk:1.4.21.1
-
cpe:2.3:a:digium:asterisk:1.4.21.2
-
cpe:2.3:a:digium:asterisk:1.4.22
-
cpe:2.3:a:digium:asterisk:1.4.22.1
-
cpe:2.3:a:digium:asterisk:1.4.22.2
-
cpe:2.3:a:digium:asterisk:1.4.23
-
cpe:2.3:a:digium:asterisk:1.4.23.1
-
cpe:2.3:a:digium:asterisk:1.4.23.2
-
cpe:2.3:a:digium:asterisk:1.4.24
-
cpe:2.3:a:digium:asterisk:1.4.24.1
-
cpe:2.3:a:digium:asterisk:1.4.25
-
cpe:2.3:a:digium:asterisk:1.4.25.1
-
cpe:2.3:a:digium:asterisk:1.4.26
-
cpe:2.3:a:digium:asterisk:1.4.26.1
-
cpe:2.3:a:digium:asterisk:1.4.26.2
-
cpe:2.3:a:digium:asterisk:1.4.26.3
-
cpe:2.3:a:digium:asterisk:1.4.27
-
cpe:2.3:a:digium:asterisk:1.4.27.1
-
cpe:2.3:a:digium:asterisk:1.4.28
-
cpe:2.3:a:digium:asterisk:1.4.29
-
cpe:2.3:a:digium:asterisk:1.4.29.1
-
cpe:2.3:a:digium:asterisk:1.4.3
-
cpe:2.3:a:digium:asterisk:1.4.30
-
cpe:2.3:a:digium:asterisk:1.4.31
-
cpe:2.3:a:digium:asterisk:1.4.32
-
cpe:2.3:a:digium:asterisk:1.4.33
-
cpe:2.3:a:digium:asterisk:1.4.33.1
-
cpe:2.3:a:digium:asterisk:1.4.34
-
cpe:2.3:a:digium:asterisk:1.4.35
-
cpe:2.3:a:digium:asterisk:1.4.36
-
cpe:2.3:a:digium:asterisk:1.4.37
-
cpe:2.3:a:digium:asterisk:1.4.38
-
cpe:2.3:a:digium:asterisk:1.4.39
-
cpe:2.3:a:digium:asterisk:1.4.39.1
-
cpe:2.3:a:digium:asterisk:1.4.39.2
-
cpe:2.3:a:digium:asterisk:1.4.4
-
cpe:2.3:a:digium:asterisk:1.4.40
-
cpe:2.3:a:digium:asterisk:1.4.40.1
-
cpe:2.3:a:digium:asterisk:1.4.40.2
-
cpe:2.3:a:digium:asterisk:1.4.41
-
cpe:2.3:a:digium:asterisk:1.4.41.1
-
cpe:2.3:a:digium:asterisk:1.4.41.2
-
cpe:2.3:a:digium:asterisk:1.4.5
-
cpe:2.3:a:digium:asterisk:1.4.6
-
cpe:2.3:a:digium:asterisk:1.4.7
-
cpe:2.3:a:digium:asterisk:1.4.7.1
-
cpe:2.3:a:digium:asterisk:1.4.8
-
cpe:2.3:a:digium:asterisk:1.4.9
-
cpe:2.3:a:digium:asterisk:1.6.2.0
-
cpe:2.3:a:digium:asterisk:1.6.2.1
-
cpe:2.3:a:digium:asterisk:1.6.2.15
-
cpe:2.3:a:digium:asterisk:1.6.2.16
-
cpe:2.3:a:digium:asterisk:1.6.2.16.1
-
cpe:2.3:a:digium:asterisk:1.6.2.16.2
-
cpe:2.3:a:digium:asterisk:1.6.2.17
-
cpe:2.3:a:digium:asterisk:1.6.2.17.1
-
cpe:2.3:a:digium:asterisk:1.6.2.17.2
-
cpe:2.3:a:digium:asterisk:1.6.2.17.3
-
cpe:2.3:a:digium:asterisk:1.6.2.18
-
cpe:2.3:a:digium:asterisk:1.6.2.18.1
-
cpe:2.3:a:digium:asterisk:1.6.2.18.2
-
cpe:2.3:a:digium:asterisk:1.6.2.2
-
cpe:2.3:a:digium:asterisk:1.6.2.3
-
cpe:2.3:a:digium:asterisk:1.6.2.4
-
cpe:2.3:a:digium:asterisk:1.6.2.5
-
cpe:2.3:a:digium:asterisk:1.6.2.6