Cisco Wednesday issued no fewer than four security advisories:
1. Cisco Unified Communications Web-based Management Vulnerabilityadvisory.
Unified Contact Center and Intelligent Contact Management products contain a vulnerability that may result in unauthorized access to the Web-based reporting and script monitoring tool (Web View) and the web-based configuration tool (Web Admin). Cisco is working on a fix to the problem, according to its
2. Cisco Unified Communications Manager Denial of Service Vulnerabilitiesadvisory.
Cisco Unified Communications Manager (CUCM), formerly CallManager, contains two denial of service (DoS) vulnerabilities. Large volumes of UDP Session Initiation Protocol (SIP) INVITE messages may cause a resource exhaustion condition on CUCM systems resulting in a kernel panic. The CUCM Trivial File Transfer Protocol (TFTP) service contains a buffer overflow vulnerability that may result in a denial of service condition or allow a remote, unauthenticated user to execute arbitrary code. There are no workarounds for these vulnerabilities, but fixes are available, according to Cisco’s
3. Multiple Vulnerabilities in Cisco PIX and ASA Applianceadvisory.
Two crafted packet vulnerabilities exist in the Cisco PIX 500 Series Security Appliance (PIX) and the Cisco 5500 Series Adaptive Security Appliance (ASA) that may result in a reload of the device. These vulnerabilities are triggered during processing of Media Gateway Control Protocol (MGCP) packets, or during processing of Transport Layer Security (TLS) traffic that terminates on the PIX or ASA security appliance. For fixes and workarounds, see Cisco’s
4. Multiple Vulnerabilities in Firewall Services Modulehere.
Two crafted packet vulnerabilities exist in the Cisco Firewall Services Module (FWSM) that may result in a reload of the FWSM. These vulnerabilities can be triggered during the processing of HTTPS requests, or during the processing of Media Gateway Control Protocol (MGCP) packets. A third vulnerability may cause access control list (ACL) entries to not be evaluated after the access list has been manipulated. Further details
Go here for more Cisco Security Advisories
Go here for more Cisco Security Responses
Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.
Recent Cisconet blog entries
Subscribe to Network World’s Cisco News Alert, which includes a weekly digest of all Cisco Subnet items




