VDB
CVE-2009-3727
CVE-2009-3727
PUBLISHED
CVSS 5 MEDIUM
Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.3, 1.6.0.x before 1.6.0.17, and 1.6.1.x before 1.6.1.9; Business Edition A.x.x, B.x.x before B.2.5.12, C.2.x.x before C.2.4.5, and C.3.x.x before C.3.2.2; AsteriskNOW 1.5; and s800i 1.3.x before 1.3.0.5 generate different error messages depending on whether a SIP username is valid, which allows remote attackers to enumerate valid usernames via multiple crafted REGISTER messages with inconsistent usernames in the URI in the To header and the Digest in the Authorization header.
EPSS 0.72% · 72.9th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
0.72%
72.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| digium | asterisk | 1.2.0, 1.2.0, 1.2.0 |
| digium | s800i | 1.3.0, 1.3.0.2, 1.3.0.4 |
| digium | asterisknow | 1.5 |
Timeline
- Nov 10, 2009 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 3, 2023 EPSS Score
- Feb 13, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 37265 third-party-advisory
- FEDORA-2009-11126 vendor-advisory
- 37479 third-party-advisory
- 37677 third-party-advisory
- DSA-1952 vendor-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=523277 url
- https://bugzilla.redhat.com/show_bug.cgi?id=533137 url
- 36924 vdb
- FEDORA-2009-11070 vendor-advisory
- 59697 vdb
- http://downloads.asterisk.org/pub/security/AST-2009-008.html url
- 1023133 vdb
- https://nvd.nist.gov/vuln/detail/CVE-2009-3727 advisory