ZeroHour
Security Affairspublished ()ingested @securityaffairs

Cisco warns of a critical bug in Unified Communications products

criticalVulnerabilityimportance 60CVE-2024-20253

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitr

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.

NVD description · AI analysis pending
10.02%
  • cisco unified communications manager
  • cisco unified communications manager im and presence service
  • cisco unity connection
  • +1 more
Full article348 words · extracted from securityaffairs.com · click to collapse

Cisco addressed a critical flaw in its Unified Communications and Contact Center Solutions products that could lead to remote code execution.

Cisco released security patches to address a critical vulnerability, tracked as CVE-2024-20253 (CVSS score of 9.9), impacting multiple Unified Communications and Contact Center Solutions products.

An unauthenticated, remote attacker can exploit the flaw to execute arbitrary code on an affected device.

The root cause of the issue is the improper processing of user-provided data that is being read into memory. An attacker can exploit the flaw by sending a crafted message to a listening port of an unpatched device. 

“This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device.” reads the advisory published by the IT giant. “A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device”

The vulnerability impacts the following products in the default configuration:

  • Unified Communications Manager (Unified CM) (CSCwd64245)
  • Unified Communications Manager IM & Presence Service (Unified CM IM&P) (CSCwd64276)
  • Unified Communications Manager Session Management Edition (Unified CM SME) (CSCwd64245)
  • Unified Contact Center Express (UCCX) (CSCwe18773)
  • Unity Connection (CSCwd64292)
  • Virtualized Voice Browser (VVB) (CSCwe18840)

There are no workarounds to fix the issue, however, the company reported that it is possible to mitigate the vulnerability by establishing access control lists (ACLs) on intermediary devices that separate the Cisco Unified Communications or Cisco Contact Center Solutions cluster from users and the rest of the network to allow access only to the ports of deployed services.

The Cisco PSIRT is not aware of attacks in the wild exploiting this flaw.

The vulnerability was reported by Julien Egloff from Synacktiv.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Unified Communications)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/158116/security/cisco-unified-communications-critical-flaw.html