Thursday, September 28, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

IP telephony: vulnerabilities in the provisioning of zoom and audio codes

Eliza Houghton by Eliza Houghton
August 17, 2023
in World
0
IP telephony: vulnerabilities in the provisioning of zoom and audio codes
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

SySS security expert Moritz Abrell discovered vulnerabilities in IP telephony using the Zoom Zero Touch provisioning process in combination with Audiocodes 400HD phones. The German presented the results of the security analysis at this year’s Black Hat USA. According to the illustrations, attackers could eavesdrop on the content of conversations, form a botnet of infected devices or attack the networks in which they are operated by compromising the end devices.

Advertisement

Provisioning in the cloud without a corporate network

In order to reduce their attack surface, IP phones are usually provisioned in protected networks in order to distribute firmware and configurations to the devices. To simplify things, with cloud-based telephony solutions such as Zoom Phone, this initial provisioning takes place without going through a secure and specially prepared environment in the corporate or government network.

With Zoom Phone, the Zero Touch Provisioning process is used to assign end devices to users and the associated configurations. The end devices load the configuration accordingly from the server if they are in the factory settings and are initially started.

svg%3E

The chain of infection.

(Image: SySS)

In the analysis, according to the analyst, any MAC addresses for the manufacturer’s phones could be stored via Zoom’s admin panel without proof of ownership of the associated device being requested. As a result, Zoom stores a redirection of the provisioning and configuration server to the Zoom server on the redirect server of the manufacturer Audiocodes – redirect.audiocodes.com. This enabled Abrell to assign a configuration template with a prepared firmware download URL to a new device via the Zoom administration. It was also possible to import multiple MAC addresses.

More vulnerabilities discovered

Advertisement

In addition, a check also revealed shortcomings when checking a firmware update. The associated checksum check could be outsmarted using a manipulated image. The phone thus installs a manipulated image after the download. In this way, attackers could, among other things, eavesdrop on conversations or penetrate internal networks.

Sensitive data such as configurations and passwords were also found during audits of the redirection paths of the Audiocodes servers. Users of the redirect service should therefore check whether their sensitive data is publicly available.

Although Abrell sent the notification to the manufacturers back in November 2022, some of the gaps are still open at the time of publication. SySS provides details on exploiting the vulnerabilities on its tech blog.

(jvo)

Home
#telephony #vulnerabilities #provisioning #zoom #audio #codes

Tags: audioAudio codecCloud ComputingcodesCorporate NetworkprovisioningSecurity VulnerabilitiesTelephonyVoIPVulnerabilitiesZoomZoom Phone
Previous Post

Constitution of the Cortes live | Vote of the Table and last minute of the Congress

Next Post

The pensions of civil servants raise the red numbers of the entire public system by 14,000 million

Eliza Houghton

Eliza Houghton

Related Posts

Actor Michael Gambon, famous for his roles as Dumbledore and Philip Marlowe, dies at 82
World

Actor Michael Gambon, famous for his roles as Dumbledore and Philip Marlowe, dies at 82

by Eliza Houghton
September 28, 2023
The Euribor reaches 4.145% in September and makes mortgages more expensive
World

The Euribor reaches 4.145% in September and makes mortgages more expensive

by Eliza Houghton
September 28, 2023
Browser: Vivaldi is now also available for iOS
World

Browser: Vivaldi is now also available for iOS

by Eliza Houghton
September 28, 2023
The Twenty-seven accelerate the unlocking of the last part that will allow the EU migration pact to be closed
World

The Twenty-seven accelerate the unlocking of the last part that will allow the EU migration pact to be closed

by Eliza Houghton
September 28, 2023
More than SQL: Find the right database for your project
World

More than SQL: Find the right database for your project

by Eliza Houghton
September 28, 2023
Next Post
The pensions of civil servants raise the red numbers of the entire public system by 14,000 million

The pensions of civil servants raise the red numbers of the entire public system by 14,000 million

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

Teams 2.0: Microsoft is apparently putting an end to the application clutter

Teams 2.0: Microsoft is apparently putting an end to the application clutter

August 25, 2023
The Government holds a “closed and confidential” meeting with the main dissidents of the FARC

The Government holds a “closed and confidential” meeting with the main dissidents of the FARC

September 1, 2023
The prosecutor in the case against Google assures that “the future of the internet” is at stake

The prosecutor in the case against Google assures that “the future of the internet” is at stake

September 12, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

Apple Artificial Intelligence attack attacks China Court Cup data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Pro Rubiales Russia Russia-Ukraine invasion Security Software development Spain Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

Apple Artificial Intelligence attack attacks China Court Cup data Death due Feijóo Germany Google government investiture iOS iPhone law live Madrid man Microsoft million news people police President Pro Rubiales Russia Russia-Ukraine invasion Security Software development Spain Sánchez time Today Ukraine Updates video Vulnerabilities war workshop world years

Recent Posts

  • Actor Michael Gambon, famous for his roles as Dumbledore and Philip Marlowe, dies at 82
  • The Euribor reaches 4.145% in September and makes mortgages more expensive
  • Browser: Vivaldi is now also available for iOS
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.