January 23, 2004

Cisco warns of IP PBX security hole

IBM hardware is affected

Cisco this week released a security bulletin warning of a vulnerability in its IP telephony software running on IBM server hardware.

The network vendor warned that a default installation of certain Cisco IP telephony software modules on could cause the IBM Director Agent on the servers to run in an insecure state, where TCP/UPD ports are left open, which could result in a system takeover or denial-of-service attack, the company says.

IBM Director Agent is software that lets users manage IBM servers remotely. The glitch in the Cisco software install leaves port 14247 open on the machine, allowing a Director Server/Console user to gain administrative privileges to the server-based IP PBX without authentication. The vulnerability could also be exploited to launch an application that forces the IBM server CPU to run at 100% utilization, forcing a reboot, according to Cisco.

Affected Cisco products include its CallManager IP PBX software, IP Call Center Express, Cisco Personal Assistant, Emergency Responder and Conference Connection applications. IBM hardware includes the IBM X330, X340, X342 and X345 servers running Windows 2000 Server. A complete list of affected products is found at http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml#affected.

Cisco has posted a script that stops the IBM Director Agent from listening to port 14247 and stops the agent from accepting connections from the port in the future. It also disables some nonessential executable files on the system that could be used to bring the server down.

Subscribe to the Security Central Newsletter

The one-stop resource center for IT professionals.

White Paper

CA Security Management Solutions

A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.

Download now! »

White paper

Beyond Compliance: The Significant Benefits of Log Management

Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.

Download now! »

Webcast

Integrated Identity Compliance: Enabling Cost-Effective Role-Based Compliance

This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.

View now! »
©1994-2009 Infoworld, Inc.