logo

Cisco Unified Communications Flaw Let Attackers Execute Arbitrary Code

ID: ccc5b937-3b1b-5d8f-b285-7807f16db166

STIX ID: report--ccc5b937-3b1b-5d8f-b285-7807f16db166

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2024-01-26

Date Updated: 2026-04-21

Author: Guru

...
...

Cisco published an advisory for CVE-2024-20253 describing a critical unauthenticated remote code execution vulnerability in several Unified Communications and Contact Center products that could allow arbitrary command execution as the web services user and potentially lead to root access. Cisco has released software updates to address the issue, advises ACL-based mitigation (no full workarounds), credits the reporter, and states there is no known public exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.