Cisco Unified Communications Flaw Let Attackers Execute Arbitrary Code
ID: ccc5b937-3b1b-5d8f-b285-7807f16db166
STIX ID: report--ccc5b937-3b1b-5d8f-b285-7807f16db166
Feed Name: cybersecurityNews.com
Threat Score
Cisco published an advisory for CVE-2024-20253 describing a critical unauthenticated remote code execution vulnerability in several Unified Communications and Contact Center products that could allow arbitrary command execution as the web services user and potentially lead to root access. Cisco has released software updates to address the issue, advises ACL-based mitigation (no full workarounds), credits the reporter, and states there is no known public exploitation to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
