Email this article   Print article 


Cisco Warns Serious VoIP Vulnerability Enables Eavesdropping

By Robert Westervelt
January 11, 2013    1:19 PM ET

Page 1 of 2

Cisco Systems is warning Cisco Unified IP Phone users that the system contains a vulnerability that opens them up to potential eavesdropping.

The networking giant issued a security advisory this week, warning that the VoIP phones contain a remote code execution zero-day vulnerability that can give an attacker access to the device's memory. The problem stems on Cisco 7900 Series devices, and the company said its engineers are working on a fix and hope to release a software update later this month.

The IP phone is a popular model used in offices globally, according to Cisco. The company said it is not aware of any attacks targeting the flaw, but the hacking technique was presented in December by security researchers Ang Cui and Michael Ossmann at the 29th Chaos Communications Conference in Hamburg, Germany. The two researchers said they believe that the weaknesses is not limited to Cisco devices.

[Related: Partners And Priorities: Cisco's Channel Chief Talks Exclusively To CRN]

Security researchers have warned about weaknesses in IP-enabled devices. Researchers at Columbia University's Intrusion Detection Systems Lab identified tens of thousands of vulnerable IP-enabled embedded devices. Despite having a small footprint, IP devices use various communication protocols that could be targeted by an attacker.

In 2009, researchers at the Black Hat conference explained how to hack into Cisco routers. The flaws they used were patched, but the researchers said the routers and other embedded devices like them are based largely on Unix and can be exploited if the attacker finds a way to navigate through the code.

In a video presentation about the Cisco IP phone hack, Cui, an embedded systems expert, said the goal of his research is to show examples of vulnerabilities in systems that can be found just about everywhere and have real world consequences. Cui said printers, phones and other devices connected to the Internet provide a platform for an attacker to leapfrog to more servers containing more sensitive data.

"Once I have access to all of these embedded systems, I can now use these guys to attack the general purpose server on your network," Cui said. "I can also use these devices to exfiltrate information from the network."

The attack can be carried out by gaining local access via the AUX port located on the rear of the device or remotely by authenticating to the device via SSH and executing malicious code. Cisco said the remote, SSH method is disabled by default on the device once it has been provisioned by a Cisco Unified Call Manager.

NEXT: Vulnerability Extends All The Way To The White House

1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...