<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Verdana;
panose-1:2 11 6 4 3 5 4 4 2 4;}
@font-face
{font-family:LucidaGrande;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
span.apple-converted-space
{mso-style-name:apple-converted-space;}
span.EmailStyle19
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Verdana",sans-serif;
color:black;
font-weight:normal;
font-style:normal;
text-decoration:none none;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle23
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Correct, malicious code in the web browser would be the exploit.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><span style="color:#595959">Ben Amick<o:p></o:p></span></p>
<p class="MsoNormal"><span style="color:#595959">Unified Communications Analyst<o:p></o:p></span></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> cisco-voip [mailto:cisco-voip-bounces@puck.nether.net]
<b>On Behalf Of </b>Lelio Fulgenzi<br>
<b>Sent:</b> Wednesday, January 10, 2018 10:59 AM<br>
<b>To:</b> James Andrewartha <jandrewartha@ccgs.wa.edu.au>; Ryan Ratliff (rratliff) <rratliff@cisco.com><br>
<b>Cc:</b> voip puck <cisco-voip@puck.nether.net><br>
<b>Subject:</b> Re: [cisco-voip] Spectre and Meltdown remediation as relevant to Cisco systems<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">But that would mean my administrator is trying to exploit the system, wouldn’t it?
<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Or are we saying that an administrator with access to the browser would click on a malicious link that would run that code?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">---<o:p></o:p></span></p>
<p class="MsoNormal"><b><span style="font-family:"Arial",sans-serif">Lelio Fulgenzi, B.A.</span></b><span style="font-family:"Arial",sans-serif"> | Senior Analyst<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif;color:#333333">Computing and Communications Services</span><span style="font-family:"Arial",sans-serif"> | University of Guelph<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">Room 037 Animal Science & Nutrition Bldg | 50 Stone Rd E | Guelph, ON | N1G 2W1<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif">519-824-4120 Ext. 56354 |
<a href="mailto:lelio@uoguelph.ca"><span style="color:#0563C1">lelio@uoguelph.ca</span></a><o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><a href="http://cp.mcafee.com/d/FZsScCQnQnTPhOqejhOYCrKrhhpvpj73AjhOrhhpvpj7ffICQkmnTDNPPXxJ55MQsCzCZXETdAdlBoG2yrqKMSdKndASRtxIrsKrgsupsvR_HYMqekQXIfzKLsKCOOVMVCZTNOavkhhmKCHtB7BgY-F6lK1FJ4Sqejt-KyCCOqerFTd79KVI04TkyTVWNfHrBHkdSBiRiVCIByV2Hsbvg5bdSaY3ivNU6CTNPRQjobZ8Qg6BKQGmGncRAIqnjh0cbvqsvd46Mgd40TVYQaC86y2fG-xbpOH0QgrgQghY_PeMCq89Rd40BaBGCy2xqA_lEr7f6Sjwe"><span style="font-family:"Arial",sans-serif">www.uoguelph.ca/ccs</span></a><span style="font-family:"Arial",sans-serif;color:#1F497D">
| @UofGCCS on Instagram, Twitter and Facebook<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-family:"Arial",sans-serif"><o:p> </o:p></span></p>
<p class="MsoNormal"><img border="0" width="187" height="100" style="width:1.9479in;height:1.0416in" id="Picture_x0020_1" src="cid:image001.png@01D38A08.29DB5D90" alt="University of Guelph Cornerstone with Improve Life tagline"><o:p></o:p></p>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> James Andrewartha [<a href="mailto:jandrewartha@ccgs.wa.edu.au">mailto:jandrewartha@ccgs.wa.edu.au</a>]
<br>
<b>Sent:</b> Wednesday, January 10, 2018 10:44 AM<br>
<b>To:</b> Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca">lelio@uoguelph.ca</a>>; Ryan Ratliff (rratliff) <<a href="mailto:rratliff@cisco.com">rratliff@cisco.com</a>><br>
<b>Cc:</b> voip puck <<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>
<b>Subject:</b> Re: [cisco-voip] Spectre and Meltdown remediation as relevant to Cisco systems<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">So long as those administrators never used a web browser when they logged in, since you can exploit Meltdown with JavaScript.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black"><o:p> </o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">-- <o:p></o:p></span></p>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">James Andrewartha<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">Network & Projects Engineer<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">Christ Church Grammar School<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">Claremont, Western Australia<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">Ph. (08) 9442 1757<o:p></o:p></span></p>
</div>
</div>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black">Mob. 0424 160 877<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size:11.5pt;font-family:"Verdana",sans-serif;color:black"><o:p> </o:p></span></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b><span style="color:black">From: </span>
</b><span style="color:black">cisco-voip <<a href="mailto:cisco-voip-bounces@puck.nether.net">cisco-voip-bounces@puck.nether.net</a>> on behalf of Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca">lelio@uoguelph.ca</a>><br>
<b>Date: </b>Wednesday, 10 January 2018 at 11:42 pm<br>
<b>To: </b>"Ryan Ratliff (rratliff)" <<a href="mailto:rratliff@cisco.com">rratliff@cisco.com</a>><br>
<b>Cc: </b>voip puck <<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>
<b>Subject: </b>Re: [cisco-voip] Spectre and Meltdown remediation as relevant to Cisco systems</span><span style="font-size:12.0pt;color:black"><o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Times New Roman",serif"><o:p> </o:p></span></p>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">OK – Just so I’m clear why the baremetal UCOS version isn’t vulnerable…<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Is it because this is a “local attack” ? And needs someone to login to the shell?<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><a href="https://tools.cisco.com/security/center/viewAlert.x?alertId=56354">https://tools.cisco.com/security/center/viewAlert.x?alertId=56354</a> : CPU hardware contains multiple vulnerabilities that could allow
a local attacker to execute arbitrary code with user privileges and gain access to sensitive information on a targeted system.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">If we were to assume that no one could log into the Window shell other than administrators, would that also be safe?<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">Sorry, silly questions, I know.<o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">---</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-family:"Arial",sans-serif">Lelio Fulgenzi, B.A.</span></b><span style="font-family:"Arial",sans-serif"> | Senior Analyst</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif;color:#333333">Computing and Communications Services</span><span style="font-family:"Arial",sans-serif"> | University of Guelph</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">Room 037 Animal Science & Nutrition Bldg | 50 Stone Rd E | Guelph, ON | N1G 2W1</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">519-824-4120 Ext. 56354 |
<a href="mailto:lelio@uoguelph.ca"><span style="color:#0563C1">lelio@uoguelph.ca</span></a></span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><a href="http://cp.mcafee.com/d/FZsS839J5Z5ZYQsCzAQsL9CXCQkmnSkNMV4QsCQkmnSkNPPX9J55BZVYsY-Urhhsd79EVLuWdPp3lpmawECSHIdzrBPpdJnor6TbCQ77Cn7ZvW_c6zBdeX3UXHTbFIIKsepLtYsyDR4klHFGTphVkffGhBrwqrjdCzATvHEFFICzCWtPhOrKr01dR8J-uIjWSVqR3tFkJkKpH9oKgGT2TQ1iPtyL0QDYu1FJYsZt4S2_id41FrJaBGBPdpb6BQQg32TSD7Ph1I43h0d-vd2Fy1EwzWLEiSsGMd46Qd44vfYPI9Cy2tjh09iFqFEwEmFfRq6NPNIdxH"><span style="font-family:"Arial",sans-serif">www.uoguelph.ca/ccs</span></a><span style="font-family:"Arial",sans-serif;color:#1F497D">
| @UofGCCS on Instagram, Twitter and Facebook</span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif"> </span><o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in"><img border="0" width="187" height="100" style="width:1.9479in;height:1.0416in" id="Picture_x005f_x0020_1" src="cid:image002.png@01D38A08.29DB5D90" alt="niversity of Guelph Cornerstone with Improve Life tagline"><o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b> Ryan Ratliff (rratliff) [<a href="mailto:rratliff@cisco.com">mailto:rratliff@cisco.com</a>]
<br>
<b>Sent:</b> Wednesday, January 10, 2018 9:11 AM<br>
<b>To:</b> Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca">lelio@uoguelph.ca</a>><br>
<b>Cc:</b> voip puck <<a href="mailto:cisco-voip@puck.nether.net">cisco-voip@puck.nether.net</a>><br>
<b>Subject:</b> Re: [cisco-voip] Spectre and Meltdown remediation as relevant to Cisco systems<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<p class="MsoNormal" style="margin-left:.5in">The only baremetal versions of those products that would require a patch are the ones that ran on Windows. Since we moved to linux root has been locked down and you can’t run custom code on the box, which is a requirement
for exploitation of this vulnerability. <o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">-Ryan <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<p class="MsoNormal" style="margin-left:.5in">On Jan 9, 2018, at 9:58 PM, Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca">lelio@uoguelph.ca</a>> wrote:<o:p></o:p></p>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"><br>
I'm wondering if products like CUCM v9 and UCCx v9 will be investigated/patched for vulnerabilities? Especially since they're bare metal compatible. </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">If Linux is affected, then wouldn't these be as well? </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">We're in the process of migrating but it would be good to know. </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"><br>
Sent from my iPhone</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in">
<span style="font-size:9.0pt;font-family:LucidaGrande"><br>
On Jan 9, 2018, at 8:32 PM, Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca"><span style="color:#954F72">lelio@uoguelph.ca</span></a>> wrote:</span><o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt;font-variant-caps: normal;orphans: auto;text-align:start;widows: auto;-webkit-text-size-adjust: auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">To be honest, I'm a little worried about the rumoured slowdown the fixes are gonna have. Will this impact the supported status of certain CPUs in collab suite?</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande"><br>
Sent from my iPhone</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:0in;margin-right:0in;margin-bottom:12.0pt;margin-left:.5in">
<span style="font-size:9.0pt;font-family:LucidaGrande"><br>
On Jan 9, 2018, at 9:47 AM, Lelio Fulgenzi <<a href="mailto:lelio@uoguelph.ca"><span style="color:#954F72">lelio@uoguelph.ca</span></a>> wrote:</span><o:p></o:p></p>
</div>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in">Good question. I’m not sure of the impact either. I _<i>suspect</i>_ that because ESXi abstracts the CPU that the intel CPU bug would affect ESXi only, not the underlying applications. Because you can’t run the
software on baremetal any longer, there shouldn’t be a need to update the voice applications.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">I’m also guessing that CIMC would likely need some updates too.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">But yes, interesting to see how this plays out.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">---</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><b><span style="font-family:"Arial",sans-serif">Lelio Fulgenzi, B.A.</span></b><span class="apple-converted-space"><span style="font-family:"Arial",sans-serif"> </span></span><span style="font-family:"Arial",sans-serif">|
Senior Analyst</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif;color:#333333">Computing and Communications Services</span><span class="apple-converted-space"><span style="font-family:"Arial",sans-serif"> </span></span><span style="font-family:"Arial",sans-serif">|
University of Guelph</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">Room 037 Animal Science & Nutrition Bldg | 50 Stone Rd E | Guelph, ON | N1G 2W1</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif">519-824-4120 Ext. 56354 |<span class="apple-converted-space"> </span><a href="mailto:lelio@uoguelph.ca"><span style="color:#954F72">lelio@uoguelph.ca</span></a></span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><a href="http://cp.mcafee.com/d/k-Kr3x0Sy-y--qejhOqenAPtPqabbXaoUsyqejqabbXaoVVZASyyO-Y-euvsdEEK6zAQsTLt6VIxGIH5gkjrlS6NJOVICSHIdzrBPq3zPbz-LZvC3hOCDtxYtRXBQSmne7cTK-ehjWyaaRQRrIEYG7DR8OJMddICPhOrLRQkQSjhPteVEVdTdw0CWAm_fm9ZrsJqxKQGmGncRAIn8lrxrW0FpKNnwqj-f0QS-euKyr1vF6y0QJSBiRiVCIBziWq81xrXjzVEwS21Ew6_fCxkN0QghZnQ9relo6y3q6y2fD-pS4Ph1eFEw4FkJkQgkbkDWJ3oVUTlO0bMt_Woat"><span style="font-family:"Arial",sans-serif">www.uoguelph.ca/ccs</span></a><span class="apple-converted-space"><span style="font-family:"Arial",sans-serif;color:#1F497D"> </span></span><span style="font-family:"Arial",sans-serif;color:#1F497D">|
@UofGCCS on Instagram, Twitter and Facebook</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-family:"Arial",sans-serif"> </span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><image001.png><o:p></o:p></p>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<div>
<p class="MsoNormal" style="margin-left:.5in"><b>From:</b><span class="apple-converted-space"> </span>cisco-voip [<a href="mailto:cisco-voip-bounces@puck.nether.net"><span style="color:#954F72">mailto:cisco-voip-bounces@puck.nether.net</span></a>]<span class="apple-converted-space"> </span><b>On
Behalf Of<span class="apple-converted-space"> </span></b>Ben Amick<br>
<b>Sent:</b><span class="apple-converted-space"> </span>Monday, January 8, 2018 4:27 PM<br>
<b>To:</b><span class="apple-converted-space"> </span>voip puck <<a href="mailto:cisco-voip@puck.nether.net"><span style="color:#954F72">cisco-voip@puck.nether.net</span></a>><br>
<b>Subject:</b><span class="apple-converted-space"> </span>[cisco-voip] Spectre and Meltdown remediation as relevant to Cisco systems<o:p></o:p></p>
</div>
</div>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">So I haven’t had much time to look into this, but has anyone else compiled a list of or needs for remediation for cisco systems for the Spectre and Meltdown vulnerabilities?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">I know the one only affects Intel and some ARM processors, whereas the other is more OS level, if I understand properly?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">So being that all the cisco telephony products are on virtualized product now, I assume that we would go to VMWare for any patching relevant to those, but I would imagine that we would also need a security patch
for the redhat/centos OS the Unified Communications products run on (and doubly so for those of us using old MCS physical chassis?)<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">It looks like routers and switches, as well as ASAs are all potentially vulnerable as well.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in">I’ve found the following articles on their website:<span class="apple-converted-space"> </span><a href="https://tools.cisco.com/security/center/viewAlert.x?alertId=56354"><span style="color:#954F72">https://tools.cisco.com/security/center/viewAlert.x?alertId=56354</span></a><span class="apple-converted-space"> </span>and<span class="apple-converted-space"> </span><a href="https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel"><span style="color:#954F72">https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel</span></a><span class="apple-converted-space"> </span>that
details the issues a bit, but it looks like Cisco hasn’t found anything yet nor delivered any patches?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="color:#595959">Ben Amick</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="color:#595959">Unified Communications Analyst</span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-left:.5in"><br>
Confidentiality Note: This message is intended for use only by the individual or entity to which it is addressed and may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is
not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received
this communication in error, please contact the sender immediately and destroy the material in its entirety, whether electronic or hard copy. Thank you<o:p></o:p></p>
</div>
</div>
</blockquote>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net"><span style="color:#954F72">cisco-voip@puck.nether.net</span></a><br>
<a href="http://cp.mcafee.com/d/FZsScCQnQnTPhOqejhOYCrKrhhpvpj73AjhOrhhpvpj7ffICQkmnTDNPPXxJ55MQsCzCZXETdAdlBoG2yrqKMSdKndASRtxIrsKrgsupsvR_HYMqekQXIfzKLsKCOOVMVCZTNOavkhhmKCHtB7BgY-F6lK1FJwSqejt-KyCCOqerFTd79KVIDeqR4INpKNnwqj-f0T1dnoovaAVgtHBFkJkKpH9oTqlblbCqOmbAaJMJZ0kIToHMd9_7wqrv7fnhdwLQzh0qmXiFqFsPmiNFtd40MJZFNYQgr10Qg3vDPgGowq88-HW4JDaI3h1J3h17P_cX2pEwDkQg2kGmGq8a5GjZmxIsYr-9iP"><span style="color:#954F72">https://puck.nether.net/mailman/listinfo/cisco-voip</span></a></span><o:p></o:p></p>
</div>
</blockquote>
</div>
</blockquote>
<blockquote style="margin-top:5.0pt;margin-bottom:5.0pt;font-variant-caps: normal;orphans: auto;text-align:start;widows: auto;-webkit-text-size-adjust: auto;-webkit-text-stroke-width: 0px;word-spacing:0px">
<div>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">_______________________________________________<br>
cisco-voip mailing list<br>
<a href="mailto:cisco-voip@puck.nether.net"><span style="color:#954F72">cisco-voip@puck.nether.net</span></a><br>
<a href="http://cp.mcafee.com/d/5fHCNAq43qbWbXVEVd79EVujdTdEEILIFzxO9EVdEEILIFzDDSjqabbXPUVVZMSyyUqejhPuZQrCO6GOIl1hdJnor6TbCOrqKMSdKndEefcKfW_R-od7aqtS7NTnKnjppsUsPuXUV5fG8EHnjlKOzOEuvkzaT0QS-rd79K_nhjjpd7dQXCzATsSjDdqymoIToHMd9_7wrwCHIcfBisEeROQGmGncRAIrJaBGBPdpb5O5mUm-wamrIlU6A_zMddLzDHECMnWhEwdbtFkJkKpH9oQKCy0om-QU-q8dwwq81LPVElcgd44vlZ2mPBm1EwSxEwzV_CtxcQgjGq81albld452R9-HgSeudV79y"><span style="color:#954F72">https://puck.nether.net/mailman/listinfo/cisco-voip</span></a></span><o:p></o:p></p>
</div>
</blockquote>
<p class="MsoNormal" style="margin-left:.5in"><span style="font-size:9.0pt;font-family:LucidaGrande">_______________________________________________<br>
cisco-voip mailing list<br>
</span><a href="mailto:cisco-voip@puck.nether.net"><span style="font-size:9.0pt;font-family:LucidaGrande;color:#954F72">cisco-voip@puck.nether.net</span></a><span style="font-size:9.0pt;font-family:LucidaGrande"><br>
</span><a href="http://cp.mcafee.com/d/FZsS96QnQnTPhOqejhOYCrKrhhpvpj73AjhOrhhpvpj7ffICQkmnTDNPPXxJ55MQsCzCZXETdAdlBoG2yrqKMSdKndASRtxIrsKrgsupsvR_HYMqekQXIfzKLsKCOOVMVCZTNOavkhhmKCHtB7BgY-F6lK1FJMSqejt-KyCCOqerFTd79KVIDeqR4INpKNnwqj-f0T1dnoovaAVgtHBFkJkKpH9oTqlblbCqOmbAaJMJZ0kIToHMd9_7wqrv7fnhdwLQzh0qmXiFqFsPmiNFtd40MJZFNYQgr10Qg3vDPgGowq88-HW4JDaI3h1J3h17P_cX2pEwDkQg2kGmGq8a5GjZmxIsYrIkbV"><span style="font-size:9.0pt;font-family:LucidaGrande;color:#954F72">https://puck.nether.net/mailman/listinfo/cisco-voip</span></a><o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="margin-left:.5in"> <o:p></o:p></p>
</div>
</div>
</body>
</html>
<BR>
Confidentiality Note: This message is intended for use only by the individual or entity to which it is addressed and may contain information that is privileged, confidential, and exempt from disclosure under applicable law. If the reader of this message is not the intended recipient or the employee or agent responsible for delivering the message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please contact the sender immediately and destroy the material in its entirety, whether electronic or hard copy. Thank you