India Broadband

Forum

 

Cisco VoIP Vulnerability Rated A 10

This is a discussion on Cisco VoIP Vulnerability Rated A 10 within the Voice over IP forums, part of the Computer technology category; Cisco has detailed two vulnerabilities in its Unified CallManager for VoIP systems. The flaws are serious - Symantec has rated ...


Go Back   India Broadband Forum > Daily dose of technology > Computer technology > Voice over IP

Register Blogs FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

 

LinkBack Thread Tools Display Modes
Old 17-07-2006, 01:18 AM   #1
 
Admin's Avatar
 
Join Date: Jan 2006
Location: New Delhi
Age: 31
Posts: 3,694
Rep Power: 10 Admin is on a distinguished road
Default Cisco VoIP Vulnerability Rated A 10

Cisco has detailed two vulnerabilities in its Unified CallManager for VoIP systems. The flaws are serious - Symantec has rated the flaws a 10 out of a possible 10.

The are two flaws are reportedly in the command line management interface (CLI) for Cisco's Unified CallManager 5.0. The flaws would allow a logged-in administrator to gain root access privileges and execute code, overwrite files, and launch denial of service attacks, Cisco said.

CallManager 5.0 also includes a buffer overflow vulnerability that attackers can exploit by placing excessively long hostnames into SIP requests along with malicious code, paving the way for code execution and denial of service attacks, according to this report.

Cisco's Product Security Incident Response Team (PSIRT) plans to make software available to address the vulnerabilities.

Symantec rated the flaws so seriously in its DeepSight Threat Management System as they do not require an exploit.

The threat may be mitigated depending on the way the VoIP solution is deployed. To prevent unauthorised access, CallManager 5.0 solutions should be implemented using VLANs and access control lists that limit access to the actual call processing servers, suggests one solutions provider.

Cisco also revealed a vulnerability that affects the Cisco Router Web Setup tool (CRWS), used to configure routers. This flaw hinges on the application's failure to properly authenticate remote Web-based users, and could allow an attacker to gain elevated administration privileges.
Admin is online now   Reply With Quote
Reply

Bookmarks

Tags
cisco, rated, voip, vulnerability


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
How VoIP Works Admin Voice over IP 1 07-01-2009 12:04 PM
Will VoIP Join the Telco Counterrevolution? India Broadband Voice over IP 0 17-07-2006 09:04 AM
Cisco Details New VoIP, Router Vulnerabilities India Broadband Voice over IP 0 17-07-2006 08:55 AM
Microsoft’s communications plunge stirs up VoIP India Broadband Voice over IP 0 17-07-2006 08:16 AM
Voice over IP (Voice over Internet Protocol) Admin Voice over IP 0 29-01-2006 01:11 AM


All times are GMT +5.5. The time now is 06:20 PM.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
India Broadband Forum