Vulnerabilities leave Cisco voice products open to remote attack

Article

Vulnerabilities leave Cisco voice products open to remote attack

Edmund X. DeJesus, Contributor

Cisco is warning of vulnerabilities in several voice products that could allow a remote attacker to obtain unauthorized administrative control or cause a denial of service.

The default installation of Cisco's Director Agent on IBM servers

    Requires Free Membership to View

    SearchSecurity.com members gain immediate and unlimited access to breaking industry news, virus alerts, new hacker threats, highly focused security newsletters, and more -- all at no cost. Join me on SearchSecurity.com today!

    Michael S. Mimoso, Editorial Director

    By submitting your registration information to SearchSecurity.com you agree to receive email communications from TechTarget and TechTarget partners. We encourage you to read our Privacy Policy which contains important disclosures about how we collect and use your registration and other information. If you reside outside of the United States, by submitting this registration information you consent to having your personal data transferred to and processed in the United States. Your use of SearchSecurity.com is governed by our Terms of Use. You may contact us at webmaster@TechTarget.com.

leaves the Director's services in an insecure state. In particular, Director Agent listens on TCP or UDP port 14247 in such a way that a remote attacker can connect and gain administrative level control without authentication. This level of privilege allows an attacker to shut down, power off or restart the system; execute a command shell; initiate file transfers; stop or start processes, services or device drivers; modify the network configuration; and create Windows 2000 user accounts.

In addition, by scanning port 14247, an attacker can initiate a Director Agent process that will take up 100% of the CPU. This will cause a denial of service, unless the server is shut down.

The Director Agent is part of several Cisco voice products, including CallManager, IP Interactive Voice Response, IP Call Center Express, Personal Assistant, Emergency Responder and Conference Connection. The problem occurs on a variety of IBM-based servers running any version of the operating system before OS 2000.2.6.

Cisco is providing a repair script that will mitigate the vulnerabilities without needing a software upgrade. The repair script keeps the Director Agent from listening for remote connections on TCP or UDP ports 14247. If port 14247 is enabled, the Director Agent won't automatically accept connections. The script also disables certain access and control files not required for Director Server to function.