Cisco has patched a flaw in several of its unified communications products that affect the gear’s Disastery Recover Framework feature. A remote, unauthenticated user could exploit this vulnerability to execute arbitrary commands that may allow full administrative access to affected systems, says Cisco in its security advisory. Cisco also has a workaround for this problem.
Vulnerable products are:
* Cisco Unified Communications Manager (CUCM) 5.x and 6.x
* Cisco Unified Communications Manager Business Edition
* Cisco Unified Precense 1.x and 6.x
* Cisco Emergency Responder 2.x
* Cisco Mobility Manager 2.x
Most recent Cisco Security Advisory:
Cisco’s first Patch Wednesday produces five IOS alerts
Also read:
More than 100 Cisco, Avaya and Nortel VoIP security holes discovered
Go here for more Cisco Advisories
Go here for Cisco Security Responses
More from Cisco Subnet:
* H-1B crisis: Cisco has 1,504 U.S. job openings to fill* Who has the best security switch?Understanding video application behaviorIs the CCSP cert worth it?CCNP lab essentialsJeff Doyle: Understanding MPLS* More than 100 Cisco, Avaya and Nortel VoIP security holes discovered
*
*
*
*
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
– 20 useful sites for Cisco networking professionals– This month’s Cisco Subnet giveaways– Network World’s IT Buyer’s Guide: Cisco products
– Subscribe to Network World’s Cisco Alert, which includes a weekly digest of all Cisco Subnet items




