ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Network management Toolkit

Router and VoIP bugs zapped by Cisco

Joris Evers CNET News.com

Published: 19 Jan 2006 12:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Flaws in Cisco software for routers and Internet telephony could be a conduit for attacks on enterprise networks, the company has warned.

On Wednesday, it released two security alerts along with fixes for Cisco CallManager, which runs VoIP services. Two flaws exist in the software: one could allow an attacker to paralyse a Cisco IP telephony installation, the other could allow someone with read-only access to the system to gain full privileges, according to the alerts.

VoIP technology allows companies to send voice traffic over the same infrastructure they use for data traffic such as email. The technology has been growing in popularity over the past few years, because it helps businesses save on phone costs and provides more flexibility to employees.

The denial-of-service problem in CallManager exists because the software does not manage certain network connections well, leaving it vulnerable to attacks. According to the company's advisory: "This may then lead to phones not responding, phones unregistering from the Cisco CallManager, or Cisco CallManager restarting," according to the company's advisory.

The second flaw only affects CallManager systems that have multilevel administration enabled. This bug could allow an administrative user with restricted, read-only access to gain full administrative privileges by using a special URL, Cisco said in an alert.

Both flaws affect CallManager 3.2 and earlier, as well as certain versions of CallManager 3.3, 4.0 and 4.1. Cisco has fixes available.

Cisco also patched a vulnerability in its Internetwork Operating System, which runs the routers and switches that make up much of the plumbing of corporate networks and the Internet. A feature called the Stack Group Bidding Protocol in certain versions of IOS is vulnerable to a remotely exploitable denial of service condition, according to a company advisory.

An attacker could exploit the security hole by crafting a special network packet and sending that to a vulnerable Cisco system.

Cisco said: "Sending such a packet to port 9900 of an affected device will cause it to freeze and stop responding to, or passing traffic." After a delay, the device will reset, the company said. Devices that do not support or have not enabled the SGBP protocol are not affected by this vulnerability.

None of the vulnerabilities were disclosed before the advisories and Cisco said it is not aware of any malicious use of the flaws.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
102 out of 188 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Featured Talkback

Could it be that ISP’s are making this out to be a bigger problem than it actually is? We’re a small country with an internet penetration of less than 60%, for every Youtuber there’s someone who only uses the internet to check their emails, more people surf on their mobile handsets than a few years ago. Surely things should even themselves up.

By: harpless

Read full story:
Unlimited-broadband offers to go 'within a year'

On The Road Blog

iPhone heaven/iPhone hell

Steve Jobs owes me nearly two hours of my life back. Or at least he would do if I wasn't so chuffed with the iPhone that finally became mine after a bum-achingly long period propped... More

2 comments

The App store spells death to Jailbrea...

I'd love to say that the quality of Apps on the Apple App store is so superior to those made for jailbroken iPhones that no one would bother jailbreaking anymore. However, this is definitely... More

4 comments

Lenovo debuts new small-business noteb...

With Intel and Vodafone along for the ride, Lenovo today launched a brand-new SL range of small-business-focussed ThinkPads, refreshed the T series (performance), R series (mainstream)... More

Post a comment