Insufficient Randomness in Asterisk GUI HTTP Server
CVE-2008-1390

Currently unrated

Key Information:

Vendor

Asterisk

Vendor
CVE Published:
24 March 2008

What is CVE-2008-1390?

The AsteriskGUI HTTP server in various versions of Asterisk, including Open Source and Business Edition, generates manager ID values that lack sufficient randomness. This predictability allows attackers to more easily guess valid manager IDs, potentially enabling them to hijack sessions. Users of affected Asterisk versions are recommended to upgrade to the latest versions to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.