logo

Critical Cisco bug lets hackers add root users on SEG devices

ID: e9b6ea01-108c-544d-8401-44735d31864f

STIX ID: report--e9b6ea01-108c-544d-8401-44735d31864f

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-07-18

Date Updated: 2026-07-17

Author: Sergiu Gatlan

...
...

Cisco released a patch for CVE-2024-20401, a critical absolute path traversal in Security Email Gateway (SEG) content scanning that allows attackers to replace files on the appliance via crafted email attachments — potentially adding root users, altering configuration, executing arbitrary code, or causing permanent DoS. The fix is provided in Content Scanner Tools 23.3.0.4823 and later (included in AsyncOS 15.5.1-055+); affected appliances with file analysis or content filters enabled should be updated and customers should contact TAC for recovery of impacted devices. No public exploits or active exploitation have been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.