Secunia Logo  


Secunia PSI WorldMap
 
Cisco Voice Products Director Agent Insecure Default Installation
Secunia Advisory: SA10696
Release Date: 2004-01-22
Last Update: 2005-03-14
Popularity: 9,937 views

Critical:
Moderately critical
Impact: DoS
System access
Where: From local network
Solution Status: Vendor Patch

Software:Cisco Conference Connection (CCC) 1.x
Cisco Emergency Responder (CER) 1.x
Cisco Internet Service Node (ISN) 2.x
Cisco IP Call Center Express (IPCC Express)
Cisco IP Interactive Voice Response (IP IVR)
Cisco Personal Assistant Version 1.3x
Cisco Personal Assistant Version 1.4x
Cisco Unified CallManager 3.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
Cisco has reported a vulnerability in multiple voice products on the IBM platform, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Voice products running on IBM servers install the Director Agent insecurely by leaving the service on port 14247 (both TCP and UDP) accessible without requiring user authentication. This can be exploited to gain administrative control of a server.

It is also possible to make the IBM Director Agent process "twgipc.exe" consume 100% CPU resources by scanning it with a network scanner.

The vulnerability affects voice products installed on the following IBM-based servers running an OS prior to OS 2000.2.6:

* IBM X330 (8654 or 8674)
* IBM X340
* IBM X342
* IBM X345
* MCS-7815-1000
* MCS-7815I-2.0
* MCS-7835I-2.4
* MCS-7835I-3.0

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

6th Nov, 2009
New advisories: 17
New vulnerabilities: 65
Updated advisories: 21

Less // 311 views
Debian update for linux-2.6.24
Less // 296 views
Debian update for linux-2.6
Moderately // 280 views
Gentoo update for horde
Less // 295 views
Fedora update for kernel
Less // 286 views
Fedora update for kernel
Moderately // 288 views
Ubuntu update for libgd2
Moderately // 302 views
Ubuntu update for libgd2
Highly // 304 views
Fedora update for alienarena-data

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 72 views
2. Adobe Reader/Acrobat Multiple Vulnerabilities // 42 views
3. Adobe Flash Player Multiple Vulnerabilities // 38 views
4. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 38 views
5. Mozilla Firefox Multiple Vulnerabilities // 34 views
6. Google Chrome Two Vulnerabilities // 23 views
7. Microsoft XML Core Services Multiple Vulnerabilities // 19 views
8. NOS Microsystems getPlus ActiveX Control Buffer Overflow // 15 views
9. Fedora update for kernel // 11 views
10. Zeroboard Multiple Vulnerabilities // 9 views