March 24, 2015 By Douglas Bonderud 2 min read

Cisco may want to cover its ears; concerned businesses will likely have a lot to say after it was revealed that the technology firm’s IP phones are vulnerable to remote eavesdropping. As reported by Threatpost, the issue was found by Chris Watts, an Australian technology researcher. While Cisco says it is working on a new firmware version to fix the problem, what is the risk to companies using these mobile devices in the meantime?

Hear No Evil?

According to an advisory from Cisco, “A vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.”

The problem stems from an issue with authentication settings in the phone’s default configuration, allowing attackers to send a malicious XML request to these devices. In turn, this grants remote access to audio streams and the ability to make phone calls remotely.

This sounds scary, especially since the Version 7.5.5 firmware for Cisco Small Business SPA500 IP phones doesn’t yet have a fix. However, the company says there is a silver lining, since privileged access might be required to exploit the bug at any stage.

“An attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests,” Cisco noted. The word “may” is worrisome, since it implies that in some cases, high-level access might not be mandatory. It is also worth noting that another bug was discovered in both the SPA300 and 500 series phones, allowing malicious actors to carry out cross-site scripting attacks.

Speak No Evil?

This isn’t the first instance of eavesdropping in recent months. As noted by Digital Trends, several SIM card manufacturers reported in February that the National Security Agency had tried — and supposedly failed — to hack these ID cards to gain access to millions of consumer phones. And, in an even stranger case, Mashable reports Mattel’s new Hello Barbie toy is coming under fire because it eavesdrops on children by listening to what they say and then sends this data to a cloud server, where it is ostensibly used to prompt better responses from the doll. Some security experts say the toy is a privacy violation because there is no guarantee this data will be used ethically.

Companies and citizens alike don’t enjoy having their conversations tapped, even if the likelihood is slim or there are assurances the data will be safeguarded. Cisco’s vulnerability came at a critical time, since businesses are looking for ways to lock down private interactions and ensure any technology they use comes with the best protection possible. Even if the risk is slim, the fact that IP phones are now under threat of eavesdropping is hard for companies to hear.

More from

Change Healthcare attack expected to exceed $1 billion in costs

3 min read - The impact of the recent Change Healthcare cyberattack is unprecedented — and so are the costs. Rick Pollack, President and CEO of the American Hospital Association, stated, “The Change Healthcare cyberattack is the most significant and consequential incident of its kind against the U.S. healthcare system in history.”In a recent earnings call, UnitedHealth Group, the parent company of Change Healthcare, speculated on the overall data breach costs. When all is said and done, the total tally may reach $1 billion…

Remote access risks on the rise with CVE-2024-1708 and CVE-2024-1709

4 min read - On February 19, ConnectWise reported two vulnerabilities in its ScreenConnect product, CVE-2024-1708 and 1709. The first is an authentication bypass vulnerability, and the second is a path traversal vulnerability. Both made it possible for attackers to bypass authentication processes and execute remote code.While ConnectWise initially reported that the vulnerabilities had proof-of-concept but hadn’t been spotted in the wild, reports from customers quickly made it clear that hackers were actively exploring both flaws. As a result, the company created patches for…

Evolving red teaming for AI environments

2 min read - As AI becomes more ingrained in businesses and daily life, the importance of security grows more paramount. In fact, according to the IBM Institute for Business Value, 96% of executives say adopting generative AI (GenAI) makes a security breach likely in their organization in the next three years. Whether it’s a model performing unintended actions, generating misleading or harmful responses or revealing sensitive information, in the AI era security can no longer be an afterthought to innovation.AI red teaming is emerging…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today