VendorsAsteriskasterisk_business_editionc.1.0beta7
Vulnerabilities

Asterisk Asterisk Business Edition c.1.0beta7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2008-1923
The IAX2 channel driver (chan_iax2) in Asterisk 1.2 before revision 72630 and 1.4 before revision 65679, when configured to allow unauthenticated calls, sends "early audio" to an unverified source IP address of a NEW message, which allows remote attackers to cause a denial of service (traffic amplification) via a spoofed NEW message.
Published 2008-04-23 · Modified
7.1EPSS 0.014
CVE-2007-6430
Asterisk Open Source 1.2.x before 1.2.26 and 1.4.x before 1.4.16, and Business Edition B.x.x before B.2.3.6 and C.x.x before C.1.0-beta8, when using database-based registrations ("realtime") and host-based authentication, does not check the IP address when the username is correct and there is no password, which allows remote attackers to bypass authentication using a valid username.
Published 2007-12-20 · Modified
4.3EPSS 0.020