← Vulnerability feed

Vulnerability record · CVE-2008-1390 · published 24 March 2008

CVE-2008-1390: Asterisk vulnerability

Asterisk · Asterisk

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

9.3 CVSS 2.0 High EPSS 3.8% · top 10.3% CWE-255 · CWE-255
9.3CVSS 2.0 base score
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-1390 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2488Asterisk vulnerabilityThe IAX2 channel driver (chan_iax2) in Asterisk before 20070504 does not properly null terminate data, which allows remote attackers to trigger loss …EPSS 4.3%9.3CVE-2007-3762Asterisk vulnerabilityStack-based buffer overflow in the IAX2 channel driver (chan_iax2) in Asterisk before 1.2.22 and 1.4.x before 1.4.8, Business Edition before B.2.2.1,…EPSS 5.5%8.8CVE-2024-42365Asterisk vulnerabilityAsterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-…EPSS 4.7%8.8CVE-2008-1332Asterisk permissions and access controls vulnerabilityUnspecified vulnerability in Asterisk Open Source 1.2.x before 1.2.27, 1.4.x before 1.4.18.1 and 1.4.19-rc3; Business Edition A.x.x, B.x.x before B.2…EPSS 2.3%7.8CVE-2009-2346Asterisk memory buffer overflow vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.2.x before 1.2.35, 1.4.x before 1.4.26.2, 1.6.0.x before 1.6.0.15, and 1.6.1.x before 1.6.…EPSS 2.6%7.8CVE-2008-3264Asterisk appliance developer kit improper authentication vulnerabilityThe FWDOWNL firmware-download implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B…EPSS 3.4%7.8CVE-2008-3263Asterisk vulnerabilityThe IAX2 protocol implementation in Asterisk Open Source 1.0.x, 1.2.x before 1.2.30, and 1.4.x before 1.4.21.2; Business Edition A.x.x, B.x.x before …EPSS 28%7.8CVE-2007-2294Asterisk vulnerabilityThe Manager Interface in Asterisk before 1.2.18 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (crash) by using MD5 auth…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2008-1390), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.