Cisco VoIP technology open to DoS attacks

By
Follow google news

Cisco Systems said today that its Unified CallManager and Presence Server software contain a number of vulnerabilities that could permit DoS attacks.

Cisco VoIP technology open to DoS attacks
In an advisory, the networking giant said CallManager versions 3.3, 4.1, 4.2 and 5.0, in addition to Presence Server version 1.0, are affected by the flaws.

The most severe of the five vulnerabilities rated 4.7 out of 10 on Cisco's vulnerability scoring system. 

Currently there are no workarounds for the bugs, and the company is developing a permanent fix, which will be distributed when it becomes available, according to a Cisco advisory. In the meantime, users should filter traffic as described in the advisory.

Andrew Storms, director of security operations for nCircle, said the flaws are relatively easy to exploit and can result in a loss of telephone service for an enterprise.

"In one instance, simply sending a large number of [internet control] message protocol) packets to a Cisco Unified CallManager can cause the system to crash," he said.

CallManager provides processing for Cisco's  VoIP software solutions, while the Presence Server tracks the usage of those products.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Attacker embeds Claude Code in mass credential harvesting op

Attacker embeds Claude Code in mass credential harvesting op

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Log In

  |  Forgot your password?