Cisco Patches IOS Flaw | Channel Insider

Cisco Patches IOS Flaw

Switching and routing firm Cisco Systems Inc. has issued a fix for a denial-of-service vulnerability affecting versions of its flagship IOS (Internetwork Operating System) software. A security advisory from the San Jose, Calif.-based company said the flaw affects all Cisco devices that are configured for Cisco ITS (IOS Telephony Service), Cisco CME (CallManager Express) or […]

Written By
Ryan Naraine
Ryan Naraine
Jan 25, 2005
2 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Switching and routing firm Cisco Systems Inc. has issued a fix for a denial-of-service vulnerability affecting versions of its flagship IOS (Internetwork Operating System) software.

A security advisory from the San Jose, Calif.-based company said the flaw affects all Cisco devices that are configured for Cisco ITS (IOS Telephony Service), Cisco CME (CallManager Express) or SRST (Survivable Remote Site Telephony) services.

ITS, CME and SRST are features that allow a Cisco device running IOS to control IP phones using the Skinny Call Control Protocol. The company warned that a malicious hacker could send certain malformed packets to the SCCP port on an IOS device configured for ITS, CME or SRST, which may cause the target device to reload.

The attack scenario could be done repeatedly to create a denial-of-service attack against telephony devices, company officials said.

The vulnerability, which was detected and reported by researchers at SecureTest, exists because of an error within the processing of control protocol messages. It affects the 12.1YD, 12.2T, 12.3, and 12.3T release trains.

Dan Jackson, president and chief operating officer of DeepNines Technologies, said the Cisco flaw is further proof that routers could present a bigger target for malicious hackers.

“From a security standpoint, 2005 is the year that the router becomes the Achilles heel of the network,” Jackson said in a statement. “Where there’s smoke, there’s fire—meaning these won’t be the last router vulnerabilities we hear about this year.”

Check out eWEEK.com’s for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer’s Weblog.

Recommended for you...

Guardz Warns MSPs of Cloud Ransomware and BEC Risks
Aminu Abdullahi
Apr 28, 2026
LogicMonitor Adds AI-Driven Remediation to IT Platform
Aminu Abdullahi
Apr 28, 2026
Moovila CEO: MSPs Must Focus on ROI, Risk, and Reality in AI Adoption
Jordan Smith
Apr 27, 2026
Scale Computing Execs on Unified Edge, Partner-First Strategy
Jordan Smith
Apr 23, 2026
Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.