jim_duffy
Managing Editor

Cisco Unified Communications Manager, Presence Server open to attacks

Analysis
Jul 11, 20071 min

Cisco issue two security alerts today:

1. Cisco Unified Communications Manager overflow flaw

Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two overflow flaws that could make it vulnerable to denial of service attacks, or for arbitrary code to be executed. Cisco has a workaround for one of the flaws, and has fixes for these vulnerabilities.

2. Cisco Unified Communications Manager, Presence Server open to attacks

Cisco Unified Communications Manager (CUCM), formerly CallManager, and Cisco Unified Presence Server (CUPS) contain two vulnerabilities that could allow an unauthorized administrator to activate and terminate CUCM / CUPS system services and access SNMP configuration information. This may respectively result in a denial of service (DoS) condition affecting CUCM/CUPS cluster systems and the disclosure of sensitive SNMP details, including community strings. There are no workarounds for these vulnerabilities but fixes are available.

Cisco security responses

Cisco security advisories

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.