ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

VoIP Toolkit

Cisco routers open to DoS attacks

Marguerite Reardon CNET News.com

Published: 24 Jan 2005 11:55 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco routers running certain telephony features could be vulnerable to denial-of-service attacks, the company warned on Friday.

Cisco said routers running the IOS Telephony Service, Cisco CallManager Express and Survivable Remote Site Telephony features could be vulnerable. These features are embedded in the company's Internetwork Operating Software, or IOS, which is used on all of Cisco's IP routers.

The CallManager Express feature enables Cisco IP routers to handle call processing for Cisco IP phones. Survivable Remote Site Telephony gives companies with branch offices an automated backup mechanism to improve the reliability of their IP voice networks. If the wide area network link to a remote office fails and the connection to the Cisco CallManager is lost, the branches' phones would automatically be redirected to the Cisco branch router running the Survivable Remote Site Telephony feature. This router would take over and provide the same function as the CallManager. When the wide area link is restored, the phones would automatically reregister with the original Cisco CallManager.

These features all use Skinny Call Control Protocol, the primary signaling protocol for Cisco's CallManager. Cisco said in its warning that certain "malformed packets" sent to the port handling the Skinny Call Control Protocol may cause the device to reload. An attacker exploiting this bug could flood the device with malformed packets that would cause the device to reload over and over again, causing a denial-of-service attack.

Cisco notes that only devices running IOS with these telephony features are vulnerable to this sort of attack. A free software patch is available from the company to fix the problem. More information about the vulnerability is available on Cisco's Web site.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
60 out of 115 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

Cisco & VOIP Engineer - 40,000 - Leeds

With an excellent working knowledge (at least 2years) of Cisco Phone Services and VOIP and experience supporting and administering call manager/call ...

CCNA/CCNP Cisco Engineer - Routers/Switches/Firewalls - Bath

The ideal candidate will have a skill set to include as many of the following: CCNA or CCNP certified, Routers, Catalyst Switches 29xx, 35xx and ...

Cisco VoIP / IPT Engineer - Oxfordshire

Cisco Call Manager and Cisco Voice Gateways are absolute must-haves while any of the following would be beneficial: Cisco Unity voicemail, IPCC ...

Featured White Papers

See All White Papers