Cisco VoIP Vulnerability Rated A 10 Print E-mail
Written by Adam Gosling   
Thursday, 13 July 2006
Cisco has detailed two vulnerabilities in its Unified CallManager for VoIP systems. The flaws are serious - Symantec has rated the flaws a 10 out of a possible 10.

The are two flaws are reportedly in the command line management interface (CLI) for Cisco's Unified CallManager 5.0. The flaws would allow a logged-in administrator to gain root access privileges and execute code, overwrite files, and launch denial of service attacks, Cisco said.

CallManager 5.0 also includes a buffer overflow vulnerability that attackers can exploit by placing excessively long hostnames into SIP requests along with malicious code, paving the way for code execution and denial of service attacks, according to this report.

Cisco's Product Security Incident Response Team (PSIRT) plans to make software available to address the vulnerabilities.

Symantec rated the flaws so seriously in its DeepSight Threat Management System as they do not require an exploit.

The threat may be mitigated depending on the way the VoIP solution is deployed. To prevent unauthorised access, CallManager 5.0 solutions should be implemented using VLANs and access control lists that limit access to the actual call processing servers, suggests one solutions provider.

Cisco also revealed a vulnerability that affects the Cisco Router Web Setup tool (CRWS), used to configure routers. This flaw hinges on the application's failure to properly authenticate remote Web-based users, and could allow an attacker to gain elevated administration privileges.

Related news items
Newer news items
Older news items
 
mobilised

Carrier News

Ructions At Engin Signal Changing Strategy
With the 30 per cent acquisition of pure play VoIP service provider, Engin, by the Seven Network, it was only a matter of time before major upheaval filtered its way to the broadband telephony provider's staff.
Older news items
 

Industry News

Vendor News

Aspect Maps Out UC Product Plans
Contact Centre software specialists, Aspect Software, has embarked on a corporate strategy to educate the market on the part the contact centre plays in an organisation's overall unified communications strategy.
Older news items
 

VoIP Solutions

Product News

WA Dept Education Goes IP With Panasonic
The West Australian Department of Education and Training has chosen Panasonic for the upgrade of all future school telephony systems to IP-capable solutions.
Older news items