also @ TechSpot: Xbox One: Entertainment Hub First, Gaming Console Second -- But Could It Disrupt TV?

Cisco patches its VoIP against flaw

By Derek Sooman

On January 26, 2005, 1:23 PM

Cisco has identified and patched security problems in their VoIP IP telephony system. The move is in response to the discovery of potential exploits that can allow hackers to mount denial of service attacks - in theory, at least.

The vulnerability affects versions of Cisco's core Internetwork Operating System (IOS) software configured for the Cisco IOS Telephony Service (ITS), Cisco CallManager Express (CME) or Survivable Remote Site Telephony (SRST) services. By sending malformed control messages a cracker could cause devices such as VoIP routers running the vulnerable software to reload. The trick could be exploited repeatedly to create a Denial of Service (DoS) attack against targeted networks.

Cisco has an advisory here which fully discusses the problem, along with free software upgrades, and with advice on suggested workarounds.

No tags on this story

Post a new comment

Social Login & Guest Posting TechSpot Members
Login here or sign up for free,
it takes about a minute.
Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.
TechSpot on:

Subscribe to TechSpot

Get free exclusive content, learn about new features and breaking tech news.