FEATURED VIDEO
Sponsored By:
SLIDE SHOWS
As if they needed more stress, organizations are facing evolving and increasingly stringent compliance regulations from the Payment Card Industry, as well as Sarbanes-Oxley, HIPAA and others. Here are a few security compliance products that can make the audit process less excruciating.
Here are 10 of the distributor's hottest new offerings winning over solution providers.
New smartphones from Sony, Motorola and the first-ever Twitter-only mobile device -- the TwitterPeek -- headline a busy week for handset makers as the holiday shopping season heats up.
INSIDE CHANNELWEB

Cisco IP Phones Open To Attack


By Stefanie Hoffman, ChannelWeb

8:00 PM EST Thu. Feb. 14, 2008
Time to update your Cisco IP phones. Cisco Systems released multiple security advisories regarding serious vulnerabilities in its IP phones and the Unified Communications Manager -- several of which have the potential to give remote attackers the ability to execute arbitrary code.

In particular, the issues affect phones using Skinny (SCCP) and SIP. Four of the advisories warned that the buffer and heap overflows detected in the IP phones could leave users susceptible to remote exploitation. An attacker could then execute a denial of service attack or take control of an entire affected system.

Lesser errors carry the potential of exposing the IP phones to a denial of service attack, enable privilege escalation or cause vulnerable phones to reboot and interrupt client voice services.

The Cisco UCM, the call processing component of San Jose, Calif.-based Cisco's IP telephony solution, also contains a serious flaw, detected in the key parameter of the Web interface by using the http or https protocol. The error leaves vulnerable systems open to an injection attack, which could terminate an SQL call and force a connection to the back-end database. An authenticated attacker could then access sensitive information, such as usernames and password hashes stored in the database. However the error would not enable an attacker to alter or delete information.

The company has already released free software updates addressing the error. A Cisco spokesperson said that the company planned to notify users as the updated software becomes available.

Security experts recommend that users update their IP phones with the patches that are available. Workarounds are also available for several of the vulnerabilities. Experts advise that users disable almost all ways to remotely manage the device, such as internal Telnet and HTTP servers and/or the filter remote access, which will eliminate exposure to the overflow and server DoS vulnerabilities.

Cisco researchers said that so far no malicious exploits have been detected for any of the vulnerabilities.

 
Channelweb : Promofinder
FEATURED PROMOTIONS
HES/HWS 30% End User Discount
HES/HWS 30% End User Discount
DLP Monitor 20% End User Discount
DLP Monitor 20% End User Discount
RELATED BLOG >>
Photo
SpamTitan offers comprehensive e-mail security, protecting against phishing attacks, viruses, malware and, yes, spam too.
ADVERTISEMENT




CHANNEL SERVICES >>

techcareers logo Search Jobs:


  

Post Resume|Employers

Recent Post:


Network Engineer
Lawrence Berkeley National Lab seeking Network Engineer in Berkeley, CA
spacer