logo

Cisco says critical Unity Connection bug lets attackers get root

ID: c6d90c9d-c2e8-53a8-8965-84e76f5fca77

STIX ID: report--c6d90c9d-c2e8-53a8-8965-84e76f5fca77

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-01-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cisco patched a critical unauthenticated command-execution flaw (CVE-2024-20272) in Unity Connection's web management interface that could allow attackers to upload files, execute OS commands, and gain root privileges; Cisco reports no evidence of public proof-of-concept or active exploitation. The advisory also covers a PoC-backed command injection (CVE-2024-20287) in the WAP371 access point that can yield root command execution but requires admin credentials, and Cisco will not issue a firmware patch for the EOL WAP371, advising migration to newer hardware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.