jim_duffy
Managing Editor

Cisco CallManager vulnerable to hijacking

Analysis
Oct 18, 20071 min

A hole in Cisco CallManager could allow hackers to hijack user sessions, according to an alert issued by Secunia. The security vendor writes: “The security issue is caused due to the improper processing of SIP messages and can be exploited to make calls from a hijacked account by requesting a URI containing a sniffed authentication header.” Rated as “less critical” by Secunia, the flaw is currently unpatched.

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

Recent Cisconet blog entries

Subscribe to Network World’s Cisco News Alert, which includes a weekly digest of all Cisco Subnet items