Breaking News

Razer Unveils Raiju V3 Pro Samsung announces Galaxy XR headset Leica M EV1 – the first M-Camera with an integrated electronic viewfinder Micron Delivers Industry’s Highest Capacity SOCAMM2 for Low-Power DRAM in the AI Data Center KIOXIA launches EXCERIA PLUS G3 and EXCERIA G3 microSD cards for exceptional photography and video performance

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Cisco IP Phones Vulnerable To Unauthenticated Remote Calls

Enterprise & IT Mar 23,2015 0

Cisco has warned owners of its Cisco Small Business SPA 300 and 500 Series IP phones, about a vulnerability of the device sthat could allow an unauthenticated, remote attacker to access sensitive information. According to a security advisory released by Cisco, a vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.

The vulnerability is due to improper authentication settings in the default configuration. An attacker could exploit this vulnerability by sending a crafted XML request to the affected device. An exploit could allow the attacker to listen to a remote audio stream or make phone calls remotely.

Cisco has confirmed that the Cisco Small Business SPA 300 and 500 Series IP phones version 7.5.5 are vulnerable. But later versions of Cisco Small Business SPA 300 and 500 Series IP phones may also be vulnerable, the company said.

No software updates are available yet.

To exploit this vulnerability, an attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests to the targeted device. This access requirement may reduce the likelihood of a successful exploit.

Cisco advices administrators to enable XML Execution authentication in the configuration settings of affected devices. They can also help protect affected systems from external attacks by using a solid firewall strategy. In adition, admins may consider using IP-based access control lists (ACLs) to allow only trusted systems to access the affected systems.

Tags: cisco
Previous Post
BIOSTAR Reveals New Hi-Fi B85Z5 Motherboard
Next Post
Acer Launches Gaming Monitor Enabled by AMD FreeSync Technology

Related Posts

  • Cisco Announces $2.5B in Financing to Support Business Resiliency

  • Cisco Hopes to Simplify Security With New Cloud-Native Platform, SecureX

  • AMD President and CEO Lisa Su Joins Cisco's Board of Directors

  • Cisco Unveils Plan for Building Internet for the Next Decade

  • Cisco Gets Into Photonics With $2.6B Acacia Acquisition

  • Cisco Announces new Wi-Fi 6 Solutions

  • Cisco at MWC Barcelona

  • Cisco Sees More IP Traffic in the Next Five Years Than in the History of the Internet

Latest News

Razer Unveils Raiju V3 Pro
Gaming

Razer Unveils Raiju V3 Pro

Samsung announces Galaxy XR headset
Consumer Electronics

Samsung announces Galaxy XR headset

Leica M EV1 – the first M-Camera with an integrated electronic viewfinder
Cameras

Leica M EV1 – the first M-Camera with an integrated electronic viewfinder

Micron Delivers Industry’s Highest Capacity SOCAMM2 for Low-Power DRAM in the AI Data Center
Enterprise & IT

Micron Delivers Industry’s Highest Capacity SOCAMM2 for Low-Power DRAM in the AI Data Center

KIOXIA launches EXCERIA PLUS G3 and EXCERIA G3 microSD cards for exceptional photography and video performance
Cameras

KIOXIA launches EXCERIA PLUS G3 and EXCERIA G3 microSD cards for exceptional photography and video performance

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

be quiet! Pure Base 501

be quiet! Pure Base 501

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed