Critical Cisco Unified Communications RCE Bug Allows Root Access
ID: 597025f4-cab7-544f-a860-3bcb847c8584
STIX ID: report--597025f4-cab7-544f-a860-3bcb847c8584
Feed Name: Dark Reading
Date Published: 2024-01-25
Date Updated: 2026-05-05
Author: Tara Seals, Managing Editor, News, Dark Reading
A critical unauthenticated remote code execution vulnerability (CVE-2024-20253, CVSS 9.9) was disclosed in Cisco Unified Communications and Contact Center platforms; attackers can send specially crafted messages to a listening port to execute code as the web services user or gain root. Cisco published affected versions and patches and recommends mitigations such as applying updates or deploying ACLs to restrict access to service ports.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
