Cisco this week released a security bulletin warning of a vulnerability in its IP telephony software running on IBM server hardware.
The network vendor warned that a default installation of certain Cisco IP telephony software modules on could cause the IBM Director Agent on the servers to run in an insecure state, where TCP/UPD ports are left open, which could result in a system takeover or denial-of-service attack, the company says.
IBM Director Agent is software that lets users manage IBM servers remotely. The glitch in the Cisco software install leaves port 14247 open on the machine, allowing a Director Server/Console user to gain administrative privileges to the server-based IP PBX without authentication. The vulnerability could also be exploited to launch an application that forces the IBM server CPU to run at 100% utilization, forcing a reboot, according to Cisco.
Affected Cisco products include its CallManager IP PBX software, IP Call Center Express, Cisco Personal Assistant, Emergency Responder and Conference Connection applications. IBM hardware includes the IBM X330, X340, X342 and X345 servers running Windows 2000 Server. A complete list of affected products is found at http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml#affected.
Cisco has posted a script that stops the IBM Director Agent from listening to port 14247 and stops the agent from accepting connections from the port in the future. It also disables some nonessential executable files on the system that could be used to bring the server down.

Sign up to receive Security Resource Alerts
A comprehensive security management solution can help you streamline, as well as grow, your current or evolving business. In this way, a strategic security approach can help you increase your competitiveness in these challenging market conditions.
Download now! »Find out how you can effectively collect, normalize and archive enterprise-wide, security-related data that is invaluable for security investigation and compliance reporting.
Download now! »This session focuses on the intersection of role management and identity compliance, and addresses the importance of identity compliance in enterprise governance and the challenges that organizations may face in achieving it.
View now! »