Secunia Logo  


Secunia PSI WorldMap
 
Cisco Voice Products Director Agent Insecure Default Installation
Secunia Advisory: SA10696
Release Date: 2004-01-22
Last Update: 2005-03-14
Popularity: 10,010 views

Critical:
Moderately critical
Impact: DoS
System access
Where: From local network
Solution Status: Vendor Patch

Software:Cisco Conference Connection (CCC) 1.x
Cisco Emergency Responder (CER) 1.x
Cisco Internet Service Node (ISN) 2.x
Cisco IP Call Center Express (IPCC Express)
Cisco IP Interactive Voice Response (IP IVR)
Cisco Personal Assistant Version 1.3x
Cisco Personal Assistant Version 1.4x
Cisco Unified CallManager 3.x

Secunia CVSS-2 Score: Available in Secunia business solutions

Subscribe: Instant alerts on relevant vulnerabilities


Advisory Content (Page 1 of 3)[ 1 ] [ 2 ] [ 3 ]

Description:
Cisco has reported a vulnerability in multiple voice products on the IBM platform, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system.

Voice products running on IBM servers install the Director Agent insecurely by leaving the service on port 14247 (both TCP and UDP) accessible without requiring user authentication. This can be exploited to gain administrative control of a server.

It is also possible to make the IBM Director Agent process "twgipc.exe" consume 100% CPU resources by scanning it with a network scanner.

The vulnerability affects voice products installed on the following IBM-based servers running an OS prior to OS 2000.2.6:

* IBM X330 (8654 or 8674)
* IBM X340
* IBM X342
* IBM X345
* MCS-7815-1000
* MCS-7815I-2.0
* MCS-7835I-2.4
* MCS-7835I-3.0

Change Page:
[ 1 ] [ 2 ] [ 3 ]



Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

27th Nov, 2009
New advisories: 8
New vulnerabilities: 15
Updated advisories: 11

Moderately // 303 views
Ubuntu update for php5

26th Nov, 2009
New advisories: 15
New vulnerabilities: 37
Updated advisories: 48

Moderately // 458 views
SugarCRM Multiple Vulnerabilities

Solutions | More...  


Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Internet Explorer Charset Inheritance Cross-Site Scripting Vulnerability // 26 views
2. Sun Java JDK / JRE Multiple Vulnerabilities // 23 views
3. Kaspersky Anti-Virus 2010 klavemu.kdl Denial of Service Vulnerability // 21 views
4. Adobe Flash Player Multiple Vulnerabilities // 18 views
5. Adobe Reader/Acrobat Multiple Vulnerabilities // 16 views
6. Microsoft .NET Framework Multiple Vulnerabilities // 12 views
7. WinRAR Multiple Unspecified Vulnerabilities // 11 views
8. Adobe Reader / Acrobat Multiple Vulnerabilities // 9 views
9. RealNetworks RealPlayer Multiple Vulnerabilities // 9 views
10. Internet Explorer Layout Handling Memory Corruption Vulnerability // 9 views