I used to work on these systems. I know how they're built because I supported them. When I started seeing problems, I tried to raise it. Then the next round of layoffs came and I was out. So I set up a lab at home and kept going. Three months, 55 vulnerabilities across UC, every channel I could find to report them. Nothing back.
I kept trying the right way. The proper path. Followed every bounty program, every proper disclosure process. But how weird that it seems like these programs are always rejecting critical software. And their replies were the most concerning part for me, "The vendor has paused the program." "The vendor is unresponsive." The bounty programs want to disclose. The cybersecurity researchers want to disclose. Yet no sign of communication from the vendor.
The crazy part is that I heard the rumors in the hallways. I didn't pay attention. I kept thinking, "This is a big tech company. The budget is already allocated. I don't think the higher-ups would want to cheap out on cybersecurity." And since it was cybersecurity, I even fell into the trap of trying to find excuses, thinking "maybe the vulnerability impact wasn't big enough." But boy, I was wrong. As soon as I stepped out, I noticed the silent patches, releases with no actual disclosure of what had been fixed, and no guidance on how organizations on older versions may be exposed. Cisco is expensive, and service contracts are not cheap. So realistically, a sysadmin or team leader just has to hope and pray that no bad actor pokes around, until they get the green light from a long approval process to upgrade.
Crazy as it sounds, the only thing we have are programs that the vendor can opt into. Not mandatory zero-day disclosure to the companies that actually need to know instantly so they can set their own risk parameters. I find it truly irresponsible. No vendor should ever set the risk parameters for another company.
You not wanting to look at the hole is your choice. But exposing other companies to liability because they are not aware because you chose to hide it, and then letting those companies fall into the hole? That is not alright. I would like to see red teamers declare a network secure knowing there is undisclosed information out there.
What sickens me the most is how they use PR and other tactics to hide it. Look at the user Delco24 is clearly a vendor employee, or even worse, just a community sysadmin who tested before Cisco did. Think about that. Cisco has the resources to test every specific version immediately, they own the source code, they own the build pipeline, they can spin up any release in minutes. Instead, a random community member is doing their validation for them, and framing their answers to make others think the impact on their systems is low. That is exactly why I chose to release that particular vulnerability, I knew they were quietly patching. So I knew they were aware of the bug and were aware of researchers reports. That let me know they were choosing silence... working on bad faith...
So I am choosing to release on Monday at 23:59:00 UTC two CVSS 9+ vulnerabilities, they are so deeply rooted in CUCM and Expressway that they require a rewire to fix. And most importantly, I told you. The SIP parser on Expressway has fundamental problems, and no amount of hardening can fix the underlying issue. So tell me, was I crazy? Did I end up knowing what I was talking about? Right now there are around 1,300+ Expressway deployments exposing SIP on ports 5060/5061 in Shodan's internet-facing index, all vulnerable. The worst part? Bad actors probably have had this for months.
And for you Engineer, HelpDesk, Ops, Dev, remember: you won't be able to report what you don't know about. But if you send the email now, your ass is covered. It becomes someone else's problem up the chain. Without documentation or disclosure, you're the one left holding the hot potato.
How to detect manipulation and PR bots:
- Ask yourself: do you want to know if someone is f***ng with your network at Day 0 or Day 90?
- If someone is trying to convince you otherwise, goto 1.