vendor:
Asterisk
by:
Not available
5.5
CVSS
MEDIUM
User Enumeration
200
CWE
Product Name: Asterisk
Affected Version From: 1.8.4.1
Affected Version To: 1.8.4.1
Patch Exists: NO
Related CWE: Not available
CPE: a:digium:asterisk:1.8.4.1
Platforms Tested:
2011
User Enumeration Weakness in Asterisk
An attacker can exploit a weakness in Asterisk to harvest valid usernames, which can be used in brute-force attacks.
Mitigation:
Unknown