Cisco Unified Communications and Contact Center Solutions Vulnerability: Arbitrary Code Execution
Key Information
- Vendor
- Cisco
- Status
- Cisco Unified Contact Center Enterprise
- Cisco Unity Connection
- Cisco Unified Communications Manager
- Cisco Unified Contact Center Express
- Vendor
- CVE Published:
- 26 January 2024
Badges
Summary
The vulnerability identified as CVE-2024-20253 in Cisco Unified Communications Manager and Contact Center Solutions products is a critical remote code execution vulnerability with a high CVSS score of 9.9. It allows an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with web services user privileges. The affected products include Unified Communications Manager, Unified CM IM & Presence, Unified CM Sesion Management Edition, Unified Contact Center Express, Unity Connection, and Virtualized Voice Browser. There are no workarounds, but organizations are advised to apply security updates as soon as possible and establish access control lists to separate vulnerable products from their networks. There is no known exploitation in the wild by ransomware groups, but taking necessary security precautions is recommended to prevent any potential exploitation.
Affected Version(s)
Cisco Unified Contact Center Enterprise =
Cisco Unity Connection = 12.0(1)SU1
Cisco Unity Connection = 12.0(1)SU2
News Articles
How To Fix CVE-2024-20253 In Cisco Products – CyberIQs
Identified as CVE-2024-20253, a new critical Remote Code Execution (RCE) vulnerability has been revealed, posing a significant threat to Cisco Unified
10 months ago
Unmasking CVE-2024-20253 - Critical-Risk RCE Vulnerability in Cisco Unified Communications Systems - OP INNOVATE
The critical flaw CVE-2024-20253 in Cisco's systems presents a severe threat, allowing unauthenticated remote code execution. With a high severity score, it impacts multiple Cisco products, necessitating immediate patch application or, alternatively, the implementation of ACLs for interim protection
10 months ago
CVE-2024-20253: Cisco Unified Comms Remote Code Execution Vulnerability
A critical remote code execution vulnerability was found in Cisco Unified Comms products. Check out this blog to learn about Cisco CVE-2024-20253 vulnerability.
10 months ago
CVSS V3.1
Timeline
- 👾
Exploit exists.
Vulnerability started trending.
Vulnerability published.
First article discovered by Penetration Testing
Vulnerability Reserved.