More than 100 vulnerabilities exist in voice-over-IP (VoIP) hardware from vendors including Avaya, Cisco and Nortel, according to research from VoIPshield Laboratories. These vulnerabilities could be exploited by attackers to spy on companies by recording calls or even extort money from providers by threatening service outages, the company says. But VoIP product vendors say that the immediate danger is minimal.
Researchers at VoIPshield Laboratories, the research division of VoIPshield Systems, which provides security products for VoIP setups, have notified affected vendors and offered to help determine remediation measures, according to the company. The three VoIP vendors were chosen “because of their popularity in the North America market,” according to the company, but other vendors, including VoIP newcomer Microsoft, will likely come under scrutiny as well.
The vulnerabilities are presented on the company’s Web site and are “categorized based on the exploit’s most likely intent: unauthorized access, code execution, denial of service or information harvesting.” Searches by vendor are possible, and severity ratings and vendor responses and actions are also noted.
The research located 27 separate vulnerabilities in Cisco devices, most from its Unified Communications Manager line. A dozen vulnerabilities were identified in Avaya’s Communications Manager products, and five in several Nortel devices.
No Actionable Information
Kevin Flynn, senior marketing manager at Cisco for Secure Unified Communications, told us that the company was aware of the issues mentioned by VoIPshield and has been in contact with its researchers for several weeks. “It is not uncommon for researchers to bring possible vulnerabilities to Cisco’s attention. We work with the outside party to identify the precise cause of the vulnerability. We then release a software patch or other mitigation techniques to our customers,” he said.
Despite the severity rankings about the vulnerabilities, Flynn said “there is a range of seriousness to the vulnerabilities mentioned…