Breaking News

Geometric Future Unveils 2026/2027 Lineup at Computex: MODEL 9 Flagship, MODEL 7 Prototypes, New PSUs and AIO​ Amiiba Launches at COMPUTEX 2026 with Ferrofluid-Inspired Hardware LIAN LI Reveals Expansive 2026 Portfolio Focused on Airflow, Modularity, and Showcase Design ASUS Now Bundles ROG Equalizer Cable with Thor III, Strix Platinum PSUs GIGABYTE Introduces D5 Single Boost Technology, Redefining What One DIMM Can Do

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Enterprise & IT Mar 23,2015 0

Cisco has warned owners of its Cisco Small Business SPA 300 and 500 Series IP phones, about a vulnerability of the device sthat could allow an unauthenticated, remote attacker to access sensitive information. According to a security advisory released by Cisco, a vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.

The vulnerability is due to improper authentication settings in the default configuration. An attacker could exploit this vulnerability by sending a crafted XML request to the affected device. An exploit could allow the attacker to listen to a remote audio stream or make phone calls remotely.

Cisco has confirmed that the Cisco Small Business SPA 300 and 500 Series IP phones version 7.5.5 are vulnerable. But later versions of Cisco Small Business SPA 300 and 500 Series IP phones may also be vulnerable, the company said.

No software updates are available yet.

To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests to the targeted device. This access requirement may reduce the likelihood of a successful exploit.

Cisco advices administrators to enable XML Execution authentication in the configuration settings of affected devices. They can also help protect affected systems from external attacks by using a solid firewall strategy. In adition, admins may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Tags: cisco
Previous Post
BIOSTAR Reveals New Hi-Fi B85Z5 Motherboard
Next Post
Acer Launches Gaming Monitor Enabled by AMD FreeSync Technology

Related Posts

  • Cisco Announces $2.5B in Financing to Support Business Resiliency

  • Cisco Hopes to Simplify Security With New Cloud-Native Platform, SecureX

  • AMD President and CEO Lisa Su Joins Cisco's Board of Directors

  • Cisco Unveils Plan for Building Internet for the Next Decade

  • Cisco Gets Into Photonics With $2.6B Acacia Acquisition

  • Cisco Announces new Wi-Fi 6 Solutions

  • Cisco at MWC Barcelona

  • Cisco Sees More IP Traffic in the Next Five Years Than in the History of the Internet

Latest News

Geometric Future Unveils 2026/2027 Lineup at Computex: MODEL 9 Flagship, MODEL 7 Prototypes, New PSUs and AIO​
Cooling Systems

Geometric Future Unveils 2026/2027 Lineup at Computex: MODEL 9 Flagship, MODEL 7 Prototypes, New PSUs and AIO​

Amiiba Launches at COMPUTEX 2026 with Ferrofluid-Inspired Hardware
Cooling Systems

Amiiba Launches at COMPUTEX 2026 with Ferrofluid-Inspired Hardware

LIAN LI Reveals Expansive 2026 Portfolio Focused on Airflow, Modularity, and Showcase Design
Cooling Systems

LIAN LI Reveals Expansive 2026 Portfolio Focused on Airflow, Modularity, and Showcase Design

ASUS Now Bundles ROG Equalizer Cable with Thor III, Strix Platinum PSUs
Enterprise & IT

ASUS Now Bundles ROG Equalizer Cable with Thor III, Strix Platinum PSUs

GIGABYTE Introduces D5 Single Boost Technology, Redefining What One DIMM Can Do
PC components

GIGABYTE Introduces D5 Single Boost Technology, Redefining What One DIMM Can Do

Popular Reviews

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Endorfy Thock V2 Wireless Keyboard

Endorfy Thock V2 Wireless Keyboard

Soft2bet and the unseen hardware that makes instant play possible

Soft2bet and the unseen hardware that makes instant play possible

Crucial T710 2TB NVME SSD

Crucial T710 2TB NVME SSD

JSAUX 65Wh Rog Ally Battery

JSAUX 65Wh Rog Ally Battery

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed