Cisco Voice Products contain a flaw that may allow a malicious user to gain control of the server. The issue is caused by an insecure default installation of IBM Director. It is possible that the flaw may allow an attacker trivial access to administrative privileges resulting in a loss of confidentiality, integrity, and/or availability.
Classification
Unknown or Incomplete
Technical
The default installations of Cisco voice products on IBM servers will install IBM Director in unsecure state leaving TCP and UDP ports 14247 open. Any Director Server/Console agent can connect over port 14247 to gain administrative level control without requiring authentication.
Solution
The vulnerabilities are specific to Cisco voice products on IBM servers and all vulnerabilities listed in this advisory can be mitigated with the repair script without requiring an upgrade.