Cisco Call Manager Security Flaw

According to TechWeb, flaws in Cisco's Call Manager software could allow an attacker to bring down the software resulting in a DoS (denial of service) attack that will knock your VoIP-based phone system offline.

According to Internet Security Systems' (ISS) X-Force research team, Cisco's CallManager has a pair of bugs that could be exploited by hackers. Cisco has released an advisory on this bug.

In addition to a potential denial-of-service style crash, ISS explains a possible scenarion where the attacker "could redirect calls at will or even eavesdrop on conversations". Yikes!

Expect to see lots of mainsteam news outlets quoting analysts who say "This is why VoIP is not ready for prime-time." or "VoIP is suitable for residential deployments, ala Vonage, CallVantage, etc. but businesses where phone service is critical should carefully consider the implications of using VoIP."

Oh no, the sky is falling! Find a bug in VoIP and all of sudden, VoIP isn't reliable enough. Sometimes the MSM (main-stream media) goes overboard by "sensationalizing" news. The Cisco bug is important, don't get me wrong, but I will be annoyed if I read some industry analyst who states VoIP is not good, practical, or "reliable" for businesses. I'm sure they will be out there with their egos - just to get their name in lights and quoted by the major news outlets.

