Home > Security News > Cisco issues CallManager security update
Security News:
EMAIL THIS

Cisco issues CallManager security update

By Bill Brenner, Senior News Writer
30 Aug 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Cisco Systems Inc. has released a security update that addresses flaws in its CallManager and Unified Communications Manager product line. An attacker can exploit the flaws to conduct cross-site scripting and SQL injection attacks.

The San Jose, Calif.-based networking giant said in its cisco-sa-20070829-ccm advisory that the programs are vulnerable to cross-site Scripting (XSS) and SQL injection attacks in the so-called lang variable of the admin and user log-on pages. "A successful attack may allow an attacker to run JavaScript on computer systems connecting to CallManager or Unified Communications Manager servers, and has the potential to disclose information within the database," the vendor said.

Cisco CallManager (CCM) is the software-based call processing component for Cisco's IP telephony product line. Cisco Unified Communications Manager extends enterprise telephony features and capabilities to packet network devices such as IP phones, media processing devices, voice over IP (VoIP) gateways, and multimedia applications, according to the Cisco Web site. Additional services, such as unified messaging, multimedia conferencing, collaborative contact centers, and interactive multimedia response systems are made possible through open telephony APIs, Cisco said.

Danish vulnerability clearinghouse Secunia rates the flaws as moderately critical in its SA26641 advisory, describing two specific problems.

The input passed to unspecified parameters to the admin or user logon pages is not properly sanitized before being returned to the user, Secunia said. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.

Also, input passed to unspecified parameters to the admin or user logon pages is not properly sanitized before being used in SQL queries. This can be exploited to manipulate SQL queries by injecting arbitrary SQL code, Secunia said.

Secunia independently confirmed that the flaws affect Cisco CallManager and Unified Communications Manager released prior to versions 3.3(5)sr2b, 4.1(3)sr5, 4.2(3)sr2 and 4.3(1)sr1. The solution is to update to versions 3.3(5)sr2b, 4.1(3)sr5, 4.2(3)sr2, or 4.3(1)sr1.



Tags: Network Device ManagementNetwork Firewalls, Routers and SwitchesNetwork Protocols and SecurityVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Device Management
DNSSEC deployments gain momentum since Kaminsky DNS bug
Firewall rule management best practices
What are best practices for fiber optic cable security?
Enterprise UTM security: The best threat management solution?
Making the case for network security configuration management
Know when you need IDS, IPS or both
SIEM: Not for small business, nor the faint of heart
Evaluating MSSP security before taking the plunge
Ixia network security tool exposes problems
Product Review: Deepdive's DD300

Network Firewalls, Routers and Switches
Firewall rule management best practices
Should enterprises be running multiple firewalls?
What are the disadvantages of proxy-based firewalls?
IT pros find corporate firewall rules tough to navigate
PCI compliance requirement 1: Firewalls
Comparing an application proxy firewall and a gateway server firewall
Microsoft Threat Management Gateway has some drawbacks
Rising Profile
Front-end/back-end firewalls vs. chassis-based firewalls
How to configure a firewall to communicate with an upstream router

Network Protocols and Security
DNSSEC deployments gain momentum since Kaminsky DNS bug
Kaminsky interview: DNSSEC addresses cross-organizational trust and security
PCI compliance requirement 4: Encrypt transmissions
Balancing security and performance: Protecting layer 7 on the network
Swedish hacker indicted for Cisco Systems, NASA breach
How to implement PCI network segmentation
How should service providers address VoIP security issues and threats?
How to create a secure network through a shared Internet connection
Cyberattack mapping could alter security defense strategy
The case against UTM: Is there a better alternative?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
OCSP  (SearchSecurity.com)
trusted computing base  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts