Original URL: http://www.channelregister.co.uk/2008/04/07/cisco_disaster_recovery_bug/
There's trouble with the Disaster Recovery Framework (DRF) Master component in a number of unified communications products from Cisco.
The flaw (http://secunia.com/advisories/29670), which the networking giant patched late last week, enables hackers to compromise vulnerable systems. Cisco Emergency Responder, Cisco Unified Communications Manager versions 5 and 6, and Cisco Unified Presence 6.x are affected.
Failure to properly authentic requests by the DRF component means miscreants might be able to execute arbitrary commands on affected systems. Denial of service attacks are also a possibility.
Cisco's advisory can be found here (http://www.cisco.com/warp/public/707/cisco-sa-20080403-drf.shtml).
The network giant credits VoIPshield Systems with discovering the vulnerability. VoIPshield, which markets VoIP security application products, created a splash last week with claims that it had unearthed previously-undiscovered vulnerabilities and exploits associated with products from Cisco, Nortel, Avaya, and other leading vendors in the area.
It claims its knowledge (http://www.voipshield.com/company/voipshield-labs.html) of these bugs gives it the edge in protecting its clients' IP telephony systems from hacking attacks using a product called VoIPguard, which it describes as an intrusion prevention system for IP telephony systems. ®
Jumbo bug crashes Cisco anti-hacker appliances (19 June 2008)
http://www.channelregister.co.uk/2008/06/19/cisco_ips_bug/
VMware ships disaster recovery and testing software (12 May 2008)
http://www.channelregister.co.uk/2008/05/12/vmware_disaster_recovery_and_stage_manager/
Cisco hits lowered targets (7 May 2008)
http://www.channelregister.co.uk/2008/05/07/cisco_hits_targets/
Cisco hops onto patching treadmill (6 March 2008)
http://www.channelregister.co.uk/2008/03/06/cisco_patch_cycle/
Cisco plugs VoIP malware loophole (15 February 2008)
http://www.channelregister.co.uk/2008/02/15/cisco_voip_update/
VOIP and the web baffle Brit spook wiretappers (30 January 2008)
http://www.theregister.co.uk/2008/01/30/gchq_mi5_baffled_by_ip_wiretapping/
2008 - the year VoIP gets hacked? (17 January 2008)
http://www.channelregister.co.uk/2008/01/17/voip_security_2008/
Skype update plugs critical bug (10 December 2007)
http://www.channelregister.co.uk/2007/12/10/skype_stealth_update/
Cisco VoIP bug poses eavesdropping risk (29 November 2007)
http://www.channelregister.co.uk/2007/11/29/cisco_voip_bug/
© Copyright 2008