jim_duffy
Managing Editor

Multiple vulnerabilities in Cisco videoconferencing gear

Analysis
Nov 18, 20102 mins

Advisory notes holes in Linux- and VxWorks-based products

Cisco issued a security advisory this week warning of multiple vulnerabilities in its videocoferencing products. The advisory can be found here.

The vulnerabilities affect the Cisco Unified Videoconferencing 5100 series of products. Several of the vulnerabilities also affect the 5200 and 3500 series products, the advisory states.

They include unauthorized use of hardcoded usernames and passwords in Linux-based products, allowing remote access to a device; Linux-shell command injection through the product’s Web interface; unauthorized access to administrator and operator account files for the Web GUI; access to shadow password files by anyone with access to the Linux directories; a service misconfiguration in Linux-based SSH servers; the ability to exploit a flaw in a script that runs with root permissions, allowing attackers to gain write access to files, access the system or cause a denial of service; predictable session IDs, which assist in the hijacking of user sessions; and storage of Web interface credentials in cookies.

Currently, there is no fixed code available for these vulnerabilities and no workarounds exist for them, according to the advisory. Cisco recommends that impacted users contact their support organizations.

The vulnerabilities were first reported by Florent Daigniere of Matta Consulting.

More from Cisco Subnet:

All of today’s Cisco news and blogs

Cisco’s Borderless Networks vs. HP’s Converged Infrastructure

QoS Lab 4 – AutoQoS VoIP (Switch)

Cisco Bolts Into High-End Network Security — Again!

Cisco releases less expensive dual band 2×2 access point

Hidden Secrets in the Cisco ASA

Follow all Cisco Subnet bloggers on Twitter.Jim Duffy on Twitter

Follow