Cisco Unified Communications and Contact Center Solutions Vulnerability: Arbitrary Code Execution

CVE-2024-20253
10CRITICAL

Key Information

Vendor
Cisco
Status
Cisco Unified Contact Center Enterprise
Cisco Unity Connection
Cisco Unified Communications Manager
Cisco Unified Contact Center Express
Vendor
CVE Published:
26 January 2024

Badges

😄 Trended👾 Exploit Exists📰 News Worthy

Summary

The vulnerability identified as CVE-2024-20253 in Cisco Unified Communications Manager and Contact Center Solutions products is a critical remote code execution vulnerability with a high CVSS score of 9.9. It allows an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system with web services user privileges. The affected products include Unified Communications Manager, Unified CM IM & Presence, Unified CM Sesion Management Edition, Unified Contact Center Express, Unity Connection, and Virtualized Voice Browser. There are no workarounds, but organizations are advised to apply security updates as soon as possible and establish access control lists to separate vulnerable products from their networks. There is no known exploitation in the wild by ransomware groups, but taking necessary security precautions is recommended to prevent any potential exploitation.

Affected Version(s)

Cisco Unified Contact Center Enterprise =

Cisco Unity Connection = 12.0(1)SU1

Cisco Unity Connection = 12.0(1)SU2

News Articles

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit exists.

  • Vulnerability started trending.

  • Vulnerability published.

  • First article discovered by Penetration Testing

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database9 News Article(s)
.