Title : Asterisk Database Registrations Authentication Bypass Vulnerability VUPEN ID : VUPEN/ADV-2007-4260 CVE ID : CVE-2007-6430
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-19
Technical Description
A vulnerability has been identified in Asterisk, which could be exploited by attackers to bypass security restrictions. This issue is caused by an error in the the way database-based registrations (realtime) are handled, which could be exploited by attackers to impersonate any user using host-based authentication without a secret, simply by guessing the username of that user.