logo

Cisco warns of critical RCE flaw in communications software

ID: 308ba4f8-fd13-5512-b60c-daf5ef452790

STIX ID: report--308ba4f8-fd13-5512-b60c-daf5ef452790

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-01-25

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Cisco has published an advisory for CVE-2024-20253, a critical (CVSS 9.9) unauthenticated remote code execution vulnerability in multiple Unified Communications Manager and Contact Center product versions; the flaw can allow arbitrary code execution and potential root access. Cisco provides specific patched releases for each affected product, states there is no workaround (recommends applying updates), suggests ACLs as a mitigation until patches are applied, and reports no evidence of public exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.