Cisco Closes Backdoor In Unified Communications Manager

Cisco has warned of three flaws in its unified communications services that could allow a remote attacker to gain complete administrative control of a system and access and modify personal user information.

The vulnerabilities impact both the platform and application software for the Cisco Unified Communications Domain Manager (Unified CDM), which controls and manages unified communication deployments as well as associated phones and clients.

The most serious bug affects the platform software with Cisco warning that if exploited, could “allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user.”

Cisco unified communications security

“The vulnerability is due to the presence of a default SSH private key, which is stored in an insecure way on the system. An attacker could exploit this vulnerability by obtaining the SSH private key. For example, the attacker might reverse engineer the binary file of the operating system,” it continues. “This will allow the attacker to connect by using the support account to the system without requiring any form of authentication.”

Cisco has advised customers to download a software update which corrects the flaw, while it has also released a patch for a separate vulnerability affecting the Unified CDM application software which could allow a remote attacker to elevate their privileges and gain administrative access to an affected system through the use of a malicious link.

The problem has been attributed to the improper implementation of authentication and authorisation controls of the administration GUI.

Cisco says the same problem is the cause of another flaw relating to the application software that could allow an unauthorised user to access and change settings relating to phone directories, speed dials, single number reach and call forwarding, however there is no update as yet for this particular vulnerability.

Do you know all about Cisco? Take our quiz.

Steve McCaskill

Steve McCaskill is editor of TechWeekEurope and ChannelBiz. He joined as a reporter in 2011 and covers all areas of IT, with a particular interest in telecommunications, mobile and networking, along with sports technology.

Recent Posts

Alphabet Value Surges Over $2tn On Dividend Plan

Google parent Alphabet sees market capitalisation surge over $2tn on plan to over first-ever cash…

6 hours ago

Google Asks US Court To Dismiss Federal Adtech Case

Google asks Virginia federal court to dismiss case brought by US Justice Department and eight…

6 hours ago

Snap Sees Surge In Users, Ad Revenues

Snapchat parent Snap reports user growth, revenues in spite of tough competition, in what may…

7 hours ago

Shein Subject To Most Stringent EU Digital Rules

Quick-growing fast-fashion company Shein must comply with most stringent level of EU digital rules after…

7 hours ago

Intel Shares Sink As AI Surge Hits Chip Revenue

Intel shares sag after company shares gloomy revenue predictions, as data centre chip demand hit…

8 hours ago

Email Provider Complains To EU Over Reduced Google Rankings

Germany's Tuta Mail says Google broke EU's new DMA rules with March algorithm update that…

8 hours ago