Advertisement
Promo

Security threats Toolkit in association with http://ad.doubleclick.net/clk;214682528;14505427;f?http://uk.blackberry.com/ataglance/security/

Cisco reveals security blunder

Marguerite Reardon CNET News.com

Published: 20 Dec 2004 11:50 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Cisco Systems has warned customers of vulnerabilities in its communications software package and of a security tool that can be used by attackers to gain access to networks.

On Wednesday, the company issued an advisory on its Web site, warning customers of the vulnerability that affects the Cisco Unity unified communications software package versions two, three and four. It also warned of a similar problem on Cisco Guard, a tool that helps protect companies from denial-of-service attacks.

Cisco Unity is a unified communications software package that allows users to listen to email over the telephone or check voice messages from the Internet. When integrated with a third-party fax server, it can even forward faxes to any local fax machine. The problem with Cisco Unity is that it creates certain user accounts with default passwords when integrated with Microsoft's Exchange program. If the password isn't changed when Unity is installed, outside users could log on and read incoming and outgoing email messages. They could also gain access to certain administrative functions.

On Wednesday, Cisco posted a solution on its Web site. The simplest fix is to change the default passwords on the accounts. The accounts with default passwords that should be changed can be found on the Web site.

Cisco said the new version of Cisco Unity version 4.0(5), which is scheduled for release in the first quarter of 2005, will not have this problem.

In October, Cisco announced several security upgrades for its unified communications products. Specifically, it offered higher security on voice messages.

Cisco also warned about a vulnerability on Cisco Guard, an application to counter denial-of-service attacks. Like the Cisco Unity product, Cisco Guard comes with default usernames and passwords. The problem can be fixed by changing these settings. Cisco Guard versions before 3.1 are affected. Details and fixes are posted on Cisco's Web site.

Denial-of-service attacks occur when a network is flooded with so many packets that switches, routers and servers stop processing them and continuously reboot. The Cisco Guard product detects traffic anomalies and then diverts this traffic to protect the server that was targeted in the attack.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
81 out of 137 people found this useful


Full Talkback thread

0 comments

Video icon

Video

Sentry Posts Blog

Behind the Scenes: Next Gen Mobile Tec...

Behind the Scenes: Next Gen Mobile Technology Author: Eric Everson, Founder MyMobiSafe.com With infrastructure speeds continually improving at the network level of the world’s leading... More

Post a comment

Nasa hacker petition presented to Numb...

Sting's wife Trudie Styler and Janis Sharp have presented a petition to Number 10 calling for Nasa hacker Gary McKinnon not to be extradited to the US. Styler, and Sharp, who is... More

Post a comment

UK to appoint cyber-sec tsar?

The UK is to appoint a cyber security tsar along the lines of the US, according to a story in the Telegraph this morning. The story is similar to one that appeared in the Guardian... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters