Cisco Call Manager Flaw Could Invite Hackers - InformationWeek
IoT
IoT
News
News
6/19/2006
06:47 PM
50%
50%
RELATED EVENTS
The Real Impact of a Data Security Breach
Aug 02, 2017
In this webcast, experts discuss the real losses associated with a breach, both in the data center ...Read More>>

Cisco Call Manager Flaw Could Invite Hackers

The vulnerability affects versions 3.1 and higher of Call Manager, which handles call routing and call signaling functions in Cisco VoIP systems, a security vendor says.

Vulnerabilities in Cisco's Call Manager software could open the door for hackers to reconfigure VoIP settings and gain access to individual users' account information, according to researchers at Kansas City, Mo.-based solution provider FishNet Security.

In a report issued Monday, Jake Reynolds, senior security engineer at FishNet, said the vulnerability affects versions 3.1 and higher of Call Manager, which handles call routing and call signaling functions in Cisco VoIP systems. A lack of input validation and output encoding in the Web administration interface for Call Manager could allow hackers to execute cross-site scripting attacks, Reynolds wrote.

Cross site scripting attacks usually involve tricking users with access privileges into clicking on a URL in an email or Web page.

In the Call Manager scenario, attackers would send a request to the Call Manager Web interface that causes malicious JavaScript to be included. If the administrator could be tricked into submitting this tainted request, the malicious code would execute in the victim's Web browser and potentially give attackers the ability to delete or reconfigure system components and gain access to confidential user information, according to the report.

In a statement, Cisco's Product Security Incident Response Team (PSRIT) recommended that users verify link destinations before clicking on URLs.

Although there are no workarounds for the issue, Cisco has fixed the vulnerability and fixes will be incorporated in all supported CallManager trains in versions 4.3(1), 4.2(3), 4.1(3)SR4 and 3.3(5)SR3, according to the statement.

To guard against attacks, FishNet recommends that companies limit network connectivity to Call Manager wherever possible to prevent hackers from discovering public Web interfaces.

"Simple Google queries are all an attacker needs in this case to obtain the target Call Manager address. There are few compelling reasons one could present that would justify public access to Call Manager web interfaces," according to the report.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
How Enterprises Are Attacking the IT Security Enterprise
How Enterprises Are Attacking the IT Security Enterprise
To learn more about what organizations are doing to tackle attacks and threats we surveyed a group of 300 IT and infosec professionals to find out what their biggest IT security challenges are and what they're doing to defend against today's threats. Download the report to see what they're saying.
Register for InformationWeek Newsletters
White Papers
Current Issue
IT Strategies to Conquer the Cloud
Chances are your organization is adopting cloud computing in one way or another -- or in multiple ways. Understanding the skills you need and how cloud affects IT operations and networking will help you adapt.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll