Cisco VoIP technology open to DoS attacks

Powered by SC Magazine
 

Cisco Systems said today that its Unified CallManager and Presence Server software contain a number of vulnerabilities that could permit DoS attacks.

In an advisory, the networking giant said CallManager versions 3.3, 4.1, 4.2 and 5.0, in addition to Presence Server version 1.0, are affected by the flaws.

The most severe of the five vulnerabilities rated 4.7 out of 10 on Cisco's vulnerability scoring system. 

Currently there are no workarounds for the bugs, and the company is developing a permanent fix, which will be distributed when it becomes available, according to a Cisco advisory. In the meantime, users should filter traffic as described in the advisory.

Andrew Storms, director of security operations for nCircle, said the flaws are relatively easy to exploit and can result in a loss of telephone service for an enterprise.

"In one instance, simply sending a large number of [internet control] message protocol) packets to a Cisco Unified CallManager can cause the system to crash," he said.

CallManager provides processing for Cisco's  VoIP software solutions, while the Presence Server tracks the usage of those products.

Cisco VoIP technology open to DoS attacks
 
 
 
Top Stories
Matching databases to Linux distros
Reviewed: OS-repository DBMSs, MariaDB vs MySQL.
 
Coalition's NBN cost-benefit study finds in favour of MTM
FTTP costs too much, would take too long.
 
Who'd have picked a BlackBerry for the Internet of Things?
[Blog] BlackBerry has a more secure future in the physical world.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
Which is the most prevalent cyber attack method your organisation faces?




   |   View results
Phishing and social engineering
  71%
 
Advanced persistent threats
  3%
 
Unpatched or unsupported software vulnerabilities
  11%
 
Denial of service attacks
  6%
 
Insider threats
  10%
TOTAL VOTES: 768

Vote