Breaking News

EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point DJI to Showcase New Mic 3 and Full Product Portfolio at Berlin’s IFA MSI Unveils MAG 272QP QD-OLED X50 Monitor Sony completes its INZONE gaming gear range with new headsets and more GIGABYTE Announces Availability of 27” QD-OLED Gaming Monitor AORUS FO27Q5P

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Enterprise & IT Mar 23,2015 0

Cisco has warned owners of its Cisco Small Business SPA 300 and 500 Series IP phones, about a vulnerability of the device sthat could allow an unauthenticated, remote attacker to access sensitive information. According to a security advisory released by Cisco, a vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.

The vulnerability is due to improper authentication settings in the default configuration. An attacker could exploit this vulnerability by sending a crafted XML request to the affected device. An exploit could allow the attacker to listen to a remote audio stream or make phone calls remotely.

Cisco has confirmed that the Cisco Small Business SPA 300 and 500 Series IP phones version 7.5.5 are vulnerable. But later versions of Cisco Small Business SPA 300 and 500 Series IP phones may also be vulnerable, the company said.

No software updates are available yet.

To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests to the targeted device. This access requirement may reduce the likelihood of a successful exploit.

Cisco advices administrators to enable XML Execution authentication in the configuration settings of affected devices. They can also help protect affected systems from external attacks by using a solid firewall strategy. In adition, admins may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Tags: cisco
Previous Post
BIOSTAR Reveals New Hi-Fi B85Z5 Motherboard
Next Post
Acer Launches Gaming Monitor Enabled by AMD FreeSync Technology

Related Posts

  • Cisco Announces $2.5B in Financing to Support Business Resiliency

  • Cisco Hopes to Simplify Security With New Cloud-Native Platform, SecureX

  • AMD President and CEO Lisa Su Joins Cisco's Board of Directors

  • Cisco Unveils Plan for Building Internet for the Next Decade

  • Cisco Gets Into Photonics With $2.6B Acacia Acquisition

  • Cisco Announces new Wi-Fi 6 Solutions

  • Cisco at MWC Barcelona

  • Cisco Sees More IP Traffic in the Next Five Years Than in the History of the Internet

Latest News

EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point
Enterprise & IT

EnGenius Brings Wi-Fi 7 to Small Businesses with Affordable ECW510 Access Point

DJI to Showcase New Mic 3 and Full Product Portfolio at Berlin’s IFA
Drones

DJI to Showcase New Mic 3 and Full Product Portfolio at Berlin’s IFA

MSI Unveils MAG 272QP QD-OLED X50 Monitor
Consumer Electronics

MSI Unveils MAG 272QP QD-OLED X50 Monitor

Sony completes its INZONE gaming gear range with new headsets and more
Consumer Electronics

Sony completes its INZONE gaming gear range with new headsets and more

GIGABYTE Announces Availability of 27” QD-OLED Gaming Monitor AORUS FO27Q5P
Consumer Electronics

GIGABYTE Announces Availability of 27” QD-OLED Gaming Monitor AORUS FO27Q5P

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

be quiet! Light Loop 360mm

be quiet! Light Loop 360mm

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Noctua NH-D15 G2

Noctua NH-D15 G2

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Base 600 LX

be quiet! Light Base 600 LX

Soundpeats Pop Clip

Soundpeats Pop Clip

be quiet! Pure Base 501

be quiet! Pure Base 501

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed