Categories: Announcements

Security Issues Addressed for Cisco Unified Communications Manager

Cisco has announced that certain versions of Cisco Unified Communications Manager (Cisco Unified CM) are vulnerable to remote hacker attacks such as

  • Blind Structured Query Language (SQL) injection
  • Command injection
  • Privilege escalation

Temporary Fix

Cisco explains how they found out about the problem through independent researchers:

On June 6, 2013, a French security firm, Lexfo, delivered a public presentation on VoIP security that included a demonstration of multiple vulnerabilities used to compromise Cisco Unified CM. During the presentation, the researchers demonstrated a multistaged attack that chained a number of vulnerabilities, which resulted in a complete compromise of the Cisco Unified CM server. 

A Cisco Options Package (COP) file has been released as a temporary fix to shore up the weaknesses and can be found on the Cisco download page. Look for the file named:

  • cmterm-CSCuh01051-2.cop.sgn

Vulnerable Products

These versions of Cisco Unified CM are known to be vulnerable:

  • Cisco Unified Communications Manager 7.1(x)
  • Cisco Unified Communications Manager 8.5(x)
  • Cisco Unified Communications Manager 8.6(x)
  • Cisco Unified Communications Manager 9.0(x)
  • Cisco Unified Communications Manager 9.1(x)

These additional Cisco products might be vulnerable to the same products but, they haven’t been confirmed yet:

  • Cisco Emergency Responder
  • Cisco Unified Contact Center Express
  • Cisco Unified Customer Voice Portal
  • Cisco Unified Presence Server/Cisco IM and Presence Service
  • Cisco Unity Connection

Lucian Constantin at PCWorld is also reporting that Cisco has warned users of denial-of-service (DoS) attacks could affect these products:

Via Cisco and PCWorld

Nathan Miloszewski

Nate is VoIP Supply's former Content Marketing Manager.

Share
Published by
Nathan Miloszewski

Recent Posts

Watch Now: 2025 February VoIP News Update

https://youtu.be/N-lzdnATPgk?si=DSbuMOrj16Vm4B1v Your February VoIP News Update is here! up first this month is the brand-new…

2 days ago

LINKVIL by Fanvil W610H & W710H IPCT Multi-Cell Solution Webinar

https://youtu.be/n5ixmNJo62A?si=iJZ9FBON2586xgpG It's time to unleash mobility with LINKVIL by Fanvil's new multi-cell solution! This webinar…

3 days ago

How To: Upgrade & Save Money on IP Paging in Educational Environments

Before I was in digital marketing, I was a teacher. For 7/12 years I taught…

2 weeks ago

Snom D815 SIP Phone Product Feature Video & How to Connect to WiFi

https://youtu.be/kHJZnDYyQQ8?si=2ZLrtFUrnnidxWoq See the Snom D815 SIP Phone like never before in this exclusive Product Feature…

3 weeks ago

AudioCodes SBCs Receive FIPS 140-3 Certification: A Milestone in Secure Communications

AudioCodes Session Border Controllers (SBCs) have achieved a significant milestone by obtaining the FIPS 140-3…

4 weeks ago

Introducing Fanvil V66 Pro & V62 Pro: The Future of Flexibility with Bluetooth Cordless Handsets Webinar

https://youtu.be/i7c5v_wGpAY?si=wD9KrJ9gHXfUXjH2 Sit back, relax, and learn everything you need to know about the new Fanvil…

4 weeks ago