Cisco warns of flaws that could disrupt voice calls
Problems in its unified communications software could allow a denial of service attack.
Cisco has warned customers about faults in its unified communications software, which could allow for a denial of service (DoS) attack and the disruption of voice services.
A security alert said that there were faults in Cisco's unified communications manager, a call processing system that extends "enterprise telephony features" to network devices such as IP phones.
Two DoS vulnerabilities are around the processing of SIP packets. The vulnerabilities can be triggered by a malformed SIP message and cause a 'critical" process to fail, disrupting voice services.
Other DoS vulnerabilities include an issue with the tracking of network connections, and two others involving the processing of SIP and SCCP packets.
Cisco said it was not yet aware of any attacks trying to take advantage of flaws found in the advisory.
The alert was published a day after Cisco warned about problems with its Wireless LAN devices, which leave it open to a DoS attack.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
-
Switzerland edges away from Microsoft with OpenDesk trialNews The Swiss government is testing whether it can drop Microsoft in favor of an open source rival for sovereignty and resilience
-
The NCSC is calling for a crackdown on shadow AINews Organizations are urged to identify shadow AI use and tighten up security procedures
-
Cisco just launched two cyber-focused small language models: Antares-350M and Antares-1B aim to supercharge codebase analysis – and they run at a “fraction of the compute expense” of popular frontier modelsNews The Antares models unveiled by Cisco aim to cut costs in codebase analysis
-
CISOs are keen on agentic AI, but they’re not going all-in yetNews Many security leaders face acute talent shortages and are looking to upskill workers
-
Security agencies issue warning over critical Cisco Catalyst SD-WAN vulnerabilityNews Threat actors have been exploiting the vulnerability to achieve root access since 2023
-
AI is “forcing a fundamental shift” in data privacy and governanceNews Organizations are working to define and establish the governance structures they need to manage AI responsibly at scale – and budgets are going up
-
Cisco says Chinese hackers are exploiting an unpatched AsyncOS zero-day flaw – here's what we know so farNews The zero-day vulnerability affects Cisco's Secure Email Gateway and Secure Email and Web Manager appliances – here's what we know so far.
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Cisco ASA customers urged to take immediate action as NCSC, CISA issue critical vulnerability warningsNews Cisco customers are urged to upgrade and secure systems immediately
-
Cisco eyes network security gains for agentic AINews New network security updates aim to secure AI agents across enterprises