Security News Letter

January 26, 2004

 

 
   Download ZoneAlarm Pro

 Download ZoneAlarm Pro Here    

Download eEye's Retina Vulnerability Scanner Here

   Get SpyWare Killer direct from Anonymizer.com!

 

Cisco warns of IP PBX security hole
IBM hardware is affected
 
By Phil Hochmuth,   Network World 

Cisco this week released a security bulletin warning of a vulnerability in its IP telephony software running on IBM server hardware. 

he network vendor warned that a default installation of certain Cisco IP telephony software modules on could cause the IBM Director Agent on the servers to run in an insecure state, where TCP/UPD ports are left open, which could result in a system takeover or denial-of-service attack, the company says. 
IBM Director Agent is software that lets users manage IBM servers remotely. The glitch in the Cisco software install leaves port 14247 open on the machine, allowing a Director Server/Console user to gain administrative privileges to the server-based IP PBX without authentication. The vulnerability could also be exploited to launch an application that forces the IBM server CPU to run at 100% utilization, forcing a reboot, according to Cisco. 

Affected Cisco products include its CallManager IP PBX software, IP Call Center Express, Cisco Personal Assistant, Emergency Responder and Conference Connection applications. IBM hardware includes the IBM X330, X340, X342 and X345 servers running Windows 2000 Server. A complete list of affected products is found at

http://www.cisco.com/warp/public/707/cisco-sa-20040121-voice.shtml#affected

Cisco has posted a script that stops the IBM Director Agent from listening to port 14247 and stops the agent from accepting connections from the port in the future. It also disables some nonessential executable files on the system that could be used to bring the server down

 

 

Security Products:

 

Intrusion Detection Systems

Vulnerability Scanners

Firewalls

  • Netscreen
  • Checkpoint

Management

Virus Control

  • Mail Marshall

Services

  • Security audit
  • Perimeter Vulnerability Scan
  • Router/ switch optimization for security
  • Firewall checking and configuration
  • VPN Design and Implementation
  • Network design
  • network based application analysis
  • Network Baselining
  • Security baselining

 

 

 

 

 

 

Copyright © 2003 Aavex Technology