jim_duffy
Managing Editor

Cisco VoIP vulnerabilities revealed today

Analysis
Jun 25, 20082 mins

Cisco’s VoIP customers need to pay attention to its expected announcement today that its call server software has vulnerabilities. The VoIP security company VoIPshield says Cisco gear and

that of its two chief rivals, Avaya and Nortel, have vulnerabilities that leave their systems open to a range of attacks. Cisco has been told about the vulnerabilities and may have fixes for them today, but that is not clear. VoIPshield says one of the three companies will just issue an advisory about its flaws but not fixes.

VoIPshield has an ongoing program to probe the VoIP platforms of the big three in corporate VoIP sales, and found vulnerabilities earlier. It releases its results three times a year after it has told the affected vendors about them and given them time to come up with a response. Clearly it’s good business for VoIPshield, which sells VoIP security products, because if VoIP gear has security flaws, it will sell more of its protection. But it’s also good for customers who haven’t got the time to perform vulnerability testing of their own. It might even be good for Cisco and its competitors that apparently aren’t finding these flaws on their own. As long as they move to fix them in a timely fashion, it’s not an indictment of their products. The software hasn’t been written that wasn’t subject to some revisions.

More from Cisco Subnet:More Cisco Security advisories and patches

Nexus vs. Catalyst 6500

One or two more years before WiMAX will be hot

CCIE sentenced in Cisco SMARTnet fraud

Cisco’s vision for the virtual data center

Free books, training, gift certificates — giveaways for June from Cisco Subnet

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.