Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Router and VoIP bugs zapped by Cisco

Joris Evers CNET News

Published: 19 Jan 2006 12:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Flaws in Cisco software for routers and Internet telephony could be a conduit for attacks on enterprise networks, the company has warned.

On Wednesday, it released two security alerts along with fixes for Cisco CallManager, which runs VoIP services. Two flaws exist in the software: one could allow an attacker to paralyse a Cisco IP telephony installation, the other could allow someone with read-only access to the system to gain full privileges, according to the alerts.

VoIP technology allows companies to send voice traffic over the same infrastructure they use for data traffic such as email. The technology has been growing in popularity over the past few years, because it helps businesses save on phone costs and provides more flexibility to employees.

The denial-of-service problem in CallManager exists because the software does not manage certain network connections well, leaving it vulnerable to attacks. According to the company's advisory: "This may then lead to phones not responding, phones unregistering from the Cisco CallManager, or Cisco CallManager restarting," according to the company's advisory.

The second flaw only affects CallManager systems that have multilevel administration enabled. This bug could allow an administrative user with restricted, read-only access to gain full administrative privileges by using a special URL, Cisco said in an alert.

Both flaws affect CallManager 3.2 and earlier, as well as certain versions of CallManager 3.3, 4.0 and 4.1. Cisco has fixes available.

Cisco also patched a vulnerability in its Internetwork Operating System, which runs the routers and switches that make up much of the plumbing of corporate networks and the Internet. A feature called the Stack Group Bidding Protocol in certain versions of IOS is vulnerable to a remotely exploitable denial of service condition, according to a company advisory.

An attacker could exploit the security hole by crafting a special network packet and sending that to a vulnerable Cisco system.

Cisco said: "Sending such a packet to port 9900 of an affected device will cause it to freeze and stop responding to, or passing traffic." After a delay, the device will reset, the company said. Devices that do not support or have not enabled the SGBP protocol are not affected by this vulnerability.

None of the vulnerabilities were disclosed before the advisories and Cisco said it is not aware of any malicious use of the flaws.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
107 out of 193 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:










Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Mobile business social network tools c...

The APIs that RIM is opening up for the BlackBerry platform leapfrog what’s available on other mobile platforms, with free push updates, unified advertising and payment options and... More

Post a comment

The Crabble stand for your phone

Sometimes something comes along that is so simple yet so very useful that you can’t believe you didn’t think of it first. The Crabble is one such object. Once upon a time smartphones... More

Post a comment

Taking Out the Skype Garbage

I don't write much about Skype any more, mostly because I find the entire company, its product and the situations surrounding it totally disgusting. However, a couple of things have... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters