Just how secure is your voice over IP (VoIP) telephony system? If it’s from Avaya, Cisco or Nortel, you may be in for a surprise. According to new research, popular products from these leading vendors contain upwards of 100 flaws that could let nogoodniks access your corporate system and steal information, or even launch denial of service (DoS) attacks in attempts to extort money from your company’s coffers. MORE ON VoIP ABC: An Introduction to VoIPDial VoIP For Vulnerability Is VoIP Set Up to Fail?Cisco, Aruba Top List of Voice Over Wi-Fi (VoWi-Fi) Ecosystem Vendors The research was released by VoIPshield Laboratories, a division of Web telephony security vendor VoIPshield Systems, and it certainly makes sense that such a vendor would want you to think you should run right out and upgrade your VoIP security. But concerns over VoIP security aren’t new. We’ve been writing about the issue at CIO for years, in fact. It seems to me that it’s only a matter of time before the potential gain from hacking such systems surpasses the time and effort it takes to crack VoIP security safeguards. Lawrence Orans, a Gartner research director, agrees. He says in a VoIPshield release that a lack of high-profile hacks or security breaches has largely lulled CIOs and CSO into a false sense of security. A March survey of 299 IT professionals by market research firm In-Stat seems back this assertion. In-Stat found that though more than 80 percent of companies have deployed some type of VoIP system across their organizations, more than half of them have no plans to secure those systems. The vulnerabilities uncovered in the Avaya, Cisco and Nortel VoIP systems are listed on VoIPshield’s website and are organized based on the most likely ways that the flaws could be exploited. For example some security flaws could be used to gain unauthorized access, execute malicious code, launch a DoS attack or steal sensitive data, according to the company. Woman Using VoIPThe flaws were also given a severity ranking based on a “modified industry standard index,” VoIPshield says. The vendor with the most vulnerabilities highlighted by the research was Cisco. Many of the vulnerabilities listed for the products examined, which include the Avaya Communications Manager 3.1.x and 4.x, Cisco Unified Communications Manager 5.x and Nortel Communications Server 1000 4.50.x, were ranked as “high” or “critical” severity. VoIPshield says it listed the vulnerabilities as part of its “Responsible Disclosure Policy” to help the companies patch the holes in their wares, and the fact that they’re publically available certainly puts pressure on the manufacturers to promptly address the issues. VoIPshield says that it chose to investigate Avaya, Cisco and Nortel products because they’re commonly used in North America, but that it plans to probe other products from other VoIP vendors, such as Microsoft, in the future. According to VoIPshield, it has notified Cisco, Avaya and Nortel with disclosure letters, and in some cases the problems have been addressed. It also uses the vulnerabilities to strengthen its own products. How concerned are you with VoIP security? Do the VoIPshield findings surprise you or make you any more concerned than in the past? Cast your vote in the poll below and let me know. AS <a href =”http://answers.polldaddy.com/poll/486302/” >How Concerned With VoIP Security Is Your Enterprise?</a> Related content brandpost Rebalancing through Recalibration: CIOs Operationalizing Pandemic-era Innovation By Kamal Nath, CEO, Sify Technologies Jun 08, 2023 6 mins CIO Digital Transformation brandpost It’s time to evolve beyond marketing to create meaningful metaverse moments Insights on the results of the Protiviti and Oxford University survey: Executive Outlook on the Metaverse, 2033 and Beyond By Kim Bozzella Jun 08, 2023 6 mins Digital Transformation feature 10 hottest IT jobs for salary growth in 2023 The demand for tech workers hasn’t slowed down, as rising salaries reveal the most sought-after tech professionals for 2023, according to data from Dice. By Sarah K. White Jun 08, 2023 8 mins Salaries IT Jobs Careers interview Oshkosh CIO Anu Khare on IT’s pursuit of value The specialty truck maker’s IT chief sees tech-enabled transformation being fueled by a relentless focus on strategic fit and customer value — and passionate business involvement. By Dan Roberts Jun 08, 2023 9 mins Automotive Industry Manufacturing Industry IT Strategy Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe