Cisco SIP TFTP Server Detection

medium Nessus Network Monitor Plugin ID 3764

Synopsis

The remote host is running an inherently insecure protocol or application.

Description

The remote host is running a Cisco SIP VOIP server. The device is configured to allow TFTP access. An attacker can guess the name of the image files and download the device configuration. Such information would include passwords and IDs.

Solution

Ensure that the TFTP server and associated ACLs are in alignment with corporate policies and guidelines.

Plugin Details

Severity: Medium

ID: 3764

Family: Generic

Published: 10/2/2006

Updated: 1/15/2016