March 24, 2015 By Douglas Bonderud 2 min read

Cisco may want to cover its ears; concerned businesses will likely have a lot to say after it was revealed that the technology firm’s IP phones are vulnerable to remote eavesdropping. As reported by Threatpost, the issue was found by Chris Watts, an Australian technology researcher. While Cisco says it is working on a new firmware version to fix the problem, what is the risk to companies using these mobile devices in the meantime?

Hear No Evil?

According to an advisory from Cisco, “A vulnerability in the firmware of the Cisco Small Business SPA 300 and 500 series IP phones could allow an unauthenticated, remote attacker to listen to the audio stream of an IP phone.”

The problem stems from an issue with authentication settings in the phone’s default configuration, allowing attackers to send a malicious XML request to these devices. In turn, this grants remote access to audio streams and the ability to make phone calls remotely.

This sounds scary, especially since the Version 7.5.5 firmware for Cisco Small Business SPA500 IP phones doesn’t yet have a fix. However, the company says there is a silver lining, since privileged access might be required to exploit the bug at any stage.

“An attacker may need access to trusted, internal networks behind a firewall to send crafted XML requests,” Cisco noted. The word “may” is worrisome, since it implies that in some cases, high-level access might not be mandatory. It is also worth noting that another bug was discovered in both the SPA300 and 500 series phones, allowing malicious actors to carry out cross-site scripting attacks.

Speak No Evil?

This isn’t the first instance of eavesdropping in recent months. As noted by Digital Trends, several SIM card manufacturers reported in February that the National Security Agency had tried — and supposedly failed — to hack these ID cards to gain access to millions of consumer phones. And, in an even stranger case, Mashable reports Mattel’s new Hello Barbie toy is coming under fire because it eavesdrops on children by listening to what they say and then sends this data to a cloud server, where it is ostensibly used to prompt better responses from the doll. Some security experts say the toy is a privacy violation because there is no guarantee this data will be used ethically.

Companies and citizens alike don’t enjoy having their conversations tapped, even if the likelihood is slim or there are assurances the data will be safeguarded. Cisco’s vulnerability came at a critical time, since businesses are looking for ways to lock down private interactions and ensure any technology they use comes with the best protection possible. Even if the risk is slim, the fact that IP phones are now under threat of eavesdropping is hard for companies to hear.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today