logo

Critical Cisco Unified Communications RCE Bug Allows Root Access

ID: 597025f4-cab7-544f-a860-3bcb847c8584

STIX ID: report--597025f4-cab7-544f-a860-3bcb847c8584

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-01-25

Date Updated: 2026-05-05

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

A critical unauthenticated remote code execution vulnerability (CVE-2024-20253, CVSS 9.9) was disclosed in Cisco Unified Communications and Contact Center platforms; attackers can send specially crafted messages to a listening port to execute code as the web services user or gain root. Cisco published affected versions and patches and recommends mitigations such as applying updates or deploying ACLs to restrict access to service ports.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.