Skip Links

Network World

Brad Reese

Outrageously shocking: More than 100 Cisco, Avaya and Nortel VoIP security holes discovered

By Brad Reese on Wed, 04/02/08 - 7:54pm.
Newsletter Signup

VoIPshield - Think Your VoIP is Secure? Think Again

It is shocking and outrageous that there are more than 100 security holes in VoIP products from Cisco, Avaya and Nortel.

The flaws were discovered by VoIP security solutions vendor VoIPshield, which revealed the vulnerabilities to the public today.

Since VoIPshield Labs is continuously finding new vulnerabilities, they plan on monthly disclosures to VoIP equipment vendors followed by public disclosure.

An interesting example of an identified Cisco VoIP vulnerability revealed today, is shown below:

Example of a Cisco VoIP Vulnerability

In the above example, a potential attacker exploiting the Cisco Unified Communication Manager (UCM) vulnerability related to its Disaster Recovery Network, could obtain full access to the UCM by getting the remote shell on the attacker's machine.

Subsequently the attacker could either disable UCM completely, download all the information from UCM to the attacker's machine or upload an executable file to the UCM.

Then the attacker could force all the Cisco softphones connected to this UCM to reboot and download that executable file.

It could be a bot, Trojan or worm.

Once the executable is downloaded and executed an attacker is able to have full access to the user’s laptop running the softphone.

This scenario could be repeated when, for example, the user of the laptop connects to another UCM.


VoIPshield has been working with major VoIP vendors since last December.

Following the terms of their Responsible Disclosure Policy, VoIPshield provided all of the VoIP vendors with detailed vulnerability descriptions and enough time to reproduce and respond to them.

Different vendors responded in different ways – some of them accused VoIPshield of grandstanding, self-promotion and skirting the boundaries of ethical disclosure.

But others, specifically Cisco Systems, responded in a professional manner and acknowledged the issues and is working with VoIPshield to resolve them.


Bogdan Materna"Personally I was surprised that Cisco Systems, known for not being very forthcoming when their products are singled out because of security issues, was very professional and willing to work with us to solve these issues," said Bogdan Materna - Founder & CTO of VoIPshield.

"It was nice to see."


There are over 1.2 billion landline and over 2 billion wireless phones (there are less than 1 billion PCs).

They are all converging on common VoIP network infrastructure and becoming part of the Internet.

But as we have seen in the early days of the Internet, security problems are being downplayed or outright ignored.

Vendors are rushing to market with new applications and devices without proper security.

Users are, in most cases, not aware that their new voice infrastructure brings serious security problems and exposures.

There are simple ways of quickly assessing the security of VoIP networks, for example, by using VoIP Vulnerability Assessment tools such as VoIPauditLite, which VoIPshield makes available as a free download.

And if you want to protect your VoIP infrastructure from these attacks, you may wish to think about deploying a VoIP Intrusion Prevention System (VIPS) such as VoIPguard.

View VoIP Security Resources:

Identified VoIP Vulnerability Database
VoIP Security Industry Resources
VoIP Security White Papers
Learn About VoIP Security

View dramatization of hacking into a financial institution's VoIP telephony system and see just how vulnerable enterprise VoIP systems really are:


If YOU were a sales executive with a Cisco reseller, would YOU get FIRED for bringing up VoIP security with a potential VoIP enterprise customer?

Contact Brad Reese
http://www.BradReese.Com

Brad's Top 5 Story Picks
# 1. Cisco Mobility VP admits that he does not really know what the term Fixed Mobile Convergence means
# 2. Cisco: Video traffic to balloon 20 times in 3 years
# 3. Tackling the inadequate Nortel R&D model
# 4. Cisco has 50 executives scouring the globe for technology acquisitions
# 5. Q & A with the ex-Cisco stars who launched the hot enterprise mobility start-up, Agito Networks
Story Archives Brad Reese on Cisco Story Archives

Cisco Power Supplies

Cisco Authorized Factory Refurbished List Pricing

Cisco Repair and Hardware Troubleshooting

  

Nice!

0

Hey Bogdan, could you make me a nice hot cup of soup?

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Welcome, visitor. Register Log in
About Brad Reese on Cisco

Brad Reese cofounded BradReese.Com Cisco Refurbished, which enables affordable Cisco networks globally by assuring customer satisfaction with guaranteed one year warranties on both Cisco Repair as well as Refurbished Cisco.

Don't be shy, contact Brad Reese online or call him Toll Free:

866-864-0506

International callers may wish to call Brad by dialing:

850-364-4115

Archives
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
Categories
Allan Sulkin - founder and president of enterprise communications systems and applications consultancy - TEQConsult Group
Careers
Chambers and his Board of Dirctors urged Cisco shareholders to vote NO
China networking marketplace
Christian Brothers Investment Services notice
Cisco
Cisco TelePresence
Cisco TelePresence revenue
Cisco Unified Communications Support for Microsoft Windows 7
Cisco engineer - Kevin Murphy
Cisco has now become the target of unflattering employee reviews
Cisco is warning Unified Communications customers about NOT successfully offering support for Microsoft Windows 7
Cisco is well known as being one of the best companies to work for
Cisco stock chart for the last 10 years
Cisco will have no liability for any delay in delivery
Cisco's 1st Quarter Other Product Revenue By Fiscal Year
Cisco's F1Q10 earnings call
Cisco's Form 10-Q
Cisco's new Stock Incentive Plan as amended and restated
Cisco's upcoming annual stockholder's meeting
Daniel Berg - Skype's CTO
Data Center
Dave Donatelli - HP executive vice president and general manager of enterprise servers and networking
FNF
Father of SIP - Jonathan Rosenberg
Financial windfall for Cisco shareholders
Flexible NetFlow
Flip video camcorder
Flip video camcorder revenue
Gilbert Public School's $3.5 million network upgrade to HP
Gilbert Public Schools Board President - Thad Stump
Gilbert Public Schools assistant superintendent - Barb VeNard
Glassdoor.com is financially backed by 2 of the leading Silicon Valley venture capital firms - Benchmark Capital and Sutter Hill Ventures
HP also bid on the project
HP purchasing 3Com
HP's Converged Infrastructure strategy
HP's acquisition of 3Com
John Chambers has had some good paydays as the CEO of Cisco
LANs / WANs
Microsoft
NBAD
NetFlow
NetFlow add-ons
Network Behavior Anomaly Detection
Network Management
Popular online career and workplace community - Glassdoor.com
ProCurve ONE alliance
Proposal submitted by Christian Brothers Investment Services
Proxy resolution during Cisco's annual meeting
Rosenberg is now Skype's Chief Technology Strategist
SMB
Say on executive pay
Security
Skills and abilities of Skype CTO Daniel Berg
Skype announced Roseberg jumped ship from Cisco
Skype's Chief Technology Strategist - responsible for Skype's overall architecture and technology strategy
So how does one verify that Glassdoor's information is really from Cisco employees?
Software
Superintendent Dave Allison
TelePresence revenue
VoIP / Convergence
When Cisco used its common stock to buy Linksys and Pure Digital
Who's right about Cisco's work environment - Fortune or Glassdoor?
Windows 7
Windows 7 just not worth an all-out urgent effort by Cisco to support
Wireless / Mobile
On The Web
Twitter