February 22, 2016 By Larry Loeb 2 min read

There has been a resurgence of an exploit that targets voice-over-IP (VoIP) telephone instruments, according to a recent report from On the Wire. VoIP phones have long been a target of cyberattacks, so users should be aware of the possible vulnerability.

Based on the findings of U.K. security researcher Paul Moore, certain VoIP phones, such as those from Snom and Cisco, have default configurations that are not secure without further modification. The default setup is browser-based, but the lack of forced initial security practices can cause the instrument to be open to an exploit.

The Problem With Default Setup

Moore showed that the Snom phone’s default setup has no authentication involved when it is run after a reset. There is no default username or password, not even the admin/admin pair so often used in insecure routers.

While the setup does have an alert that shows the password has not been set, it is just a display. The setup process does not actually require that a password be set, which is the root of the problem.

This type of setup problem has happened before. CVE-2015-0670 notes how Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 did not properly support authentication, which allowed remote attackers to read audio-stream data or originate telephone calls via a crafted XML request.

About the VoIP Exploit

Moore set up a situation along with two of his researcher friends to demonstrate the vulnerability. He read one friend’s site while he had a private conversation with the other via Skype.

A video on his blog shows how the first friend forced the VoIP phone to call a premium-rate number and disabled the speaker. Unless the victim — in this case, Moore — were looking at the phone, he or she wouldn’t even know the phone was dialing.

Not only that, but the attacker could make, receive and transfer calls, play recordings, upload new firmware and even use the device for covert surveillance.

How to Prevent It

On his website, Moore recommended the four following steps to protect VoIP phones:

  1. Use strong passwords derived from a password manager.
  2. Segregate phones by virtual LAN/network, if possible.
  3. Restrict access to application programming interfaces, even if they’re only visible internally.
  4. Check and upgrade your firmware regularly, ensuring it doesn’t revert to default security settings afterward.

While these are all sound suggestions, the most pressing is to evaluate the default setup process for a VoIP phone. Simply assuming the manufacturer has automatically enabled some form of security may not be justified.

More from

Unpacking the NIST cybersecurity framework 2.0

4 min read - The NIST cybersecurity framework (CSF) helps organizations improve risk management using common language that focuses on business drivers to enhance cybersecurity.NIST CSF 1.0 was released in February 2014, and version 1.1 in April 2018. In February 2024, NIST released its newest CSF iteration: 2.0. The journey to CSF 2.0 began with a request for information (RFI) in February 2022. Over the next two years, NIST engaged the cybersecurity community through analysis, workshops, comments and draft revision to refine existing standards…

What should Security Operations teams take away from the IBM X-Force 2024 Threat Intelligence Index?

3 min read - The IBM X-Force 2024 Threat Intelligence Index has been released. The headlines are in and among them are the fact that a global identity crisis is emerging. X-Force noted a 71% increase year-to-year in attacks using valid credentials.In this blog post, I’ll explore three cybersecurity recommendations from the Threat Intelligence Index, and define a checklist your Security Operations Center (SOC) should consider as you help your organization manage identity risk.The report identified six action items:Remove identity silosReduce the risk of…

Obtaining security clearance: Hurdles and requirements

3 min read - As security moves closer to the top of the operational priority list for private and public organizations, needing to obtain a security clearance for jobs is more commonplace. Security clearance is a prerequisite for a wide range of roles, especially those related to national security and defense.Obtaining that clearance, however, is far from simple. The process often involves scrutinizing one’s background, financial history and even personal character. Let’s briefly explore some of the hurdles, expectations and requirements of obtaining a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today