r/ciscoUC

Contact Center

Hi all,

I am looking for some help or tutoring on passing Cisco's 500-443 exam advanced Administration and Reporting of Contact Center Enterprise. I was able to pass 500-442 with no issues. I have attended Sunset learnings Cisco courses. I need to be able to obtain 500-443 in order to move to my new job role within my company. I purchased a study guide and after taking the test today and failing I was able to confirm that all the study guide questions were the same questions that were on the test. So I really just need help deciphering the best answer that Cisco is looking for. If anyone can point me in the right direction that would be great, thanks!

reddit.com
u/No_Flamingo3582 — 19 hours ago

Inbound calls CNAM handling in CUCM

For inbound calls we see CNAM in the alerting message on WebEx but it looks like that CNAM isn't stored in CDR, is that expected? Is there some setting we have to enable to store CNAM? Basically we want to be able to have that in some way even if it's not in CDR.

reddit.com
u/ipadbest2 — 6 days ago

Is r/Cisco open? Or are they keeping me from posting there? Anyway, I will find a way to get the message out.

They got the almighty Mythos 5 and billions in infrastructure. I had a Chinese model that barely works and a toaster for a laptop. For them it's just "Mythos, find the vulnerability," "Mythos, fix the vulnerability," "Mythos, push the fix." So you have to wonder where are all those AI billions actually going? The vulnerabilities are still unpatched, and there's been no disclosure about how customers and networks are exposed, or since when. Keep going down this road and you are basically handing out the Decryption Key to everybody. If AI builds it, AI can find the flaws.

You may own the code. You may own the pipelines... the restaurant.  but I was the one cooking the burgers every day.

And you can't help but wonder: is this profiting off vulnerabilities? To stay secure you have to be on the latest version (which probably ships with a whole new set of undisclosed bugs), which means planning insane maintenance windows, then living through the phase where everything is broken and business operations get disrupted. All for what? A rushed release that never accounted for what the customer actually needs? Just hardening piled on top of hardening? And let's not even get into the service contracts, how much are the new licenses per device? How much is the new software? Sounds like a loop to me: stable operations -> mandatory upgrade -> six months of planning -> everything crashing every other day -> use the support contract they sold you -> repeat next year. Meanwhile you're exposed for half the cycle.

I can't wait to go public. I'm counting the days. But I have to be patient, the lawyers are making sure you can't pull anything sneaky to come after me. You may not answer me here, but we will drag you into a court of law. You might be so intoxicated with yourself, but let's see if you think you are above a judge.

Where is my last paycheck? It's been months. Who gave you the right to withhold my money... MY BREAD? We don't have slavery in this country anymore, the founding fathers took care of that. You think you get to play with people lives? My family? but don't worry. I'm a real man, and a man always provides no matter what. Even if I have to DoorDash 14 hours a day to put food on the table, I will. I always do... especially when I'm going up against somebody bigger than me.

I can't wait for trial. I can't wait for every piece of proof and evidence I have to become public record, the phone calls, the messages, all the communications. I can't wait to finally be able to talk about it. You can try to stop it, but people are going to want to hear it, and I know there are others out there who will like to come on my show and talk about what they have had to put up with.

And to everybody else reading this: really think about it. If you are not in a glass office, or if you have many peers, the layoffs are coming sooner or later. Don't be a fool. Save everything, every piece of proof, every evidence... because God forbid you may need it one day and don't have it.

Next drop as usual Monday at 23:59 PM UCT at reddit r/CiscoUC

reddit.com
u/0xReadingSteiner — 7 days ago
▲ 10 r/ciscoUC

Unity Vm to Email Microsoft Graph

Hi everyone, has someone already implemented the new EWS change for Unified Messaging through the newest Unity Version and Microsoft Graph API?

I’d like to know if the configuration is the same as the previous one using client secret and all that stuff. Or if there are huge changes that must be accounted for, either on the Unity side or the Exchange Server, feels like documentation is lacking for this one

reddit.com
u/hmujica — 9 days ago

Any idea how to get a authenticated trunk (like VoIP.ms) to work on cucm?

I tried some stuff, it didn't work, my router did have sip alg on I believe, I'm gonna try another network,but if anyone has any tips, lmk!

reddit.com
u/RJphones — 13 days ago

Jabber client: Join public MUC room

Hello everyone,

On Jabber client (in my case on Windows), i'd like to join some public MUC rooms like we do with other XMPP clients.
It seems there is no option to join a room by its JID.

Am I just blind or what? :D

Thank you much :)

reddit.com
u/ponay95 — 11 days ago

What to do with a DX80

I work in education and funding isn't exactly plentiful. We recently shut down an office and among the equipment returned are a few DX80 units. I setup one up on my desk to see if it's worth keeping. The unit went total EoL at the end of January and as such, it does work but not well. It's a nice external monitor and it can join meetings but there's no controls access to the controls anymore so I can't switch between the monitor feed and the meeting feed. Unfortunately, I can't leave or end a meeting I'm in unless I restart the unit with the power button. I can't access the setting from the device's IP address because I don't have a login. We left our on-prem CUCM so there's nothing to register it to locally. Is this just a fancy screen now or is there anything else I can use it for?

reddit.com
u/SquareheadinNH — 13 days ago

Two days ago I dropped a CVSS 10.0 pre-auth RCE chain on Cisco CUCM (Silent;Call). Today I'm releasing the tool that shows what happens next - and it's worse than the RCE itself. - FG#001 Phantom-Phone-Tap is LIVE NOW

Two days ago I published **Silent;Call** — a pre-authentication remote root chain on Cisco Unified Communications Manager 15.x. Three HTTP requests, zero credentials, root access. CVSS 10.0.

https://github.com/0xReadingSteiner/Silent-Call

The response I keep hearing: "OK, so you get root on a phone server. What's the actual impact?"

So I built the answer.

FG#001 — Phantom Phone Tap demonstrates exactly what an attacker does after landing on CUCM. The post-exploitation is worse than the initial compromise — because CUCM was designed to do all of this. No additional exploits. No malware. No logs.

https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

---

What a compromised CUCM gives an attacker

TAP — Silent Call Interception

Silently join any active phone call in the enterprise. Both sides stream to you in real-time. Recorded and transcribed. Neither party gets any indication — no beep, no light, no notification. Built-In Bridge was designed for "call quality monitoring." It's a wiretap.

SPY — Room Surveillance

Turn any IP phone into a live room microphone. The speakerphone activates silently — no ring, no screen change, no LED. Every conference room and executive office becomes a listening post.

Track — Communication Intelligence

Full call history for any extension. Who called whom, when, for how long, from which device. Map communication patterns across the entire org.

Org — Cross-Cluster Worm

Enumerate the entire cluster. Every phone, every user, every trunk. Surface high-value targets by title — CEO, CFO, General Counsel. Enable wiretap on every phone in the enterprise with one SQL UPDATE. Zero audit trail.

And the worst part: it doesn't stop at one cluster. Org discovers other CUCM clusters via SIP trunk OPTIONS pings — intercluster trunks, B2B trunks to partner orgs, PSTN trunks to telcos. Each discovered CUCM gets fingerprinted and tested against the same Silent;Call chain. Same hardcoded creds. Same pre-auth RCE. Same root.

A hospital trunked to a clinic. A law firm trunked to a client. A government agency trunked to a contractor. A carrier trunked to hundreds of enterprises. One compromised CUCM worms through the entire trunk mesh.

---

# Your privacy is already gone

This isn't theoretical. If any CUCM in the trunk mesh is compromised, everyone on the other end loses their privacy protections — and they'll never know.

Regular Americans — your calls through any enterprise, hospital, or government office running CUCM can be silently intercepted. No notification. No consent. No recourse.

Senators and Congress members — your office phones, committee rooms, Capitol Hill lines all route through CUCM. Classified briefings, legislative negotiations — interceptable without a warrant, without FISA, without oversight.

Lawyers — attorney-client privilege ceases to exist on a compromised CUCM. Opposing counsel or a state actor could be listening to your case strategy in real-time. Your client's Sixth Amendment right to counsel — gone.

Doctors and healthcare workers — every patient call over a Cisco IP phone becomes a HIPAA violation the moment that CUCM is compromised. Protected Health Information flowing through intercepted calls. Federal penalties up to $1.5M per violation category per year.

Financial sector — intercepted executive calls expose material non-public information. That's insider trading fuel. Gramm-Leach-Bliley requires you to protect customer financial data — your phone system just handed it away.

Federal laws this violates:

- Wiretap Act (18 U.S.C. § 2511) — silent interception is a federal felony, up to 5 years per count
- ECPA — real-time interception and CDR exfiltration both covered
- HIPAA — intercepted medical calls expose Protected Health Information
- GLBA — financial customer data exposed via intercepted calls
- SOX — compromised executive communications enable insider trading
- FERPA — student records discussed over university CUCM phones
- Fourth Amendment — warrantless surveillance on government CUCM deployments
- CALEA — CUCM's own lawful intercept features used WITHOUT court authorization
- State wiretap laws — criminal offense in 12 all-party-consent states: CA, FL, IL, MD, MA, PA, CT, WA, OR, MT, NH, HI

Cisco claims 300,000+ CUCM deployments worldwide. The US federal government is one of their largest customers. Every military branch, most federal agencies, majority of the Fortune 500. When Silent;Call propagates through SIP trunks cluster to cluster, the entire US voice infrastructure built on Cisco is at risk.

This is not a vulnerability in a niche product. This is a vulnerability in the phone system.

---

# There is no detection

Silent;Call gives you root. That's bad. But the terrifying part is what root means on CUCM:

- There is no audit trail when Built-In Bridge is enabled via SQL
- There is no indicator on the phone when it's being tapped
- There is no SIEM event when auto-answer is activated remotely
- There is no detection mechanism for any of this

The wiretap capability is a feature — it just has no access controls, no logging, and no user notification.

---

# Sysadmins — check your exposure right now

Before you do anything else, run this on your CUCM CLI:

run sql select name, tkstatus_builtinbridge from device where tkclass = 1

Any phone showing tkstatus_builtinbridge = 2 has wiretap capability already enabled. If you didn't enable it, someone else did — or it's been on since deployment and nobody noticed.

The FG#001 README has a full 9-step hardening guide: SSH restriction, BIB auditing, voice VLAN segmentation, SQL monitoring, and what Cisco should provide but doesn't.

---

# Why I'm publishing this

Cisco PSIRT was notified. ZDI has 17 of my CUCM submissions sitting unprocessed. SSD paused all Cisco acquisitions because Cisco won't address existing reports. No CVEs assigned. No acknowledgment. No fix timeline.

This is advisory 1 of 55. Silent;Call is the entry point. FG#001 shows the impact. More kill chains are coming weekly.

Tool + hardening guide: https://github.com/0xReadingSteiner/FG001-phantom-phone-tap

Full research campaign: https://github.com/0xReadingSteiner/cisco-security-research

Contact: 0xReadingSteiner@proton.me

---

*FG#001 requires legitimate admin credentials (or the access Silent;Call provides). It does not introduce any new vulnerability — it demonstrates capabilities already present in every CUCM deployment.*

github.com
u/0xReadingSteiner — 14 days ago

Cisco DX80 touch screen control board

Hi everyone,

I'm planning to buy a Cisco DX80 for around €40 with the goal of reusing the display as a touchscreen for a Raspberry Pi.

My plan is to:Remove the Cisco motherboard.

Install a universal HDMI/LVDS LCD controller board to drive the LCD.

Reuse the original capacitive touchscreen if possible.

While taking a look inside, I found that the touch controller board is marked:

SiS9250B0GA3 + SiS9203_LGE_23"_V04

The board connects to the touch sensor via four ribbon cables and has a single 4-pin connector going to the Cisco motherboard.

My main question:

Does anyone know what interface that 4-pin connection uses?

Is it USB?

I²C?

UART?

Something proprietary?

If it's USB, there's a good chance I can connect it directly to the Raspberry Pi and keep the original touchscreen working.

Also, does anyone know the exact LCD panel model used in the DX80?

If anyone has disassembled I'd really appreciate any information.

Thanks a lot!

u/andersonmottabr — 12 days ago