Cisco Fixes High-Risk Vulnerability Impacting Unity Connection Software
ID: a209e0d0-49c8-5fe7-83ed-bb52859789ab
STIX ID: report--a209e0d0-49c8-5fe7-83ed-bb52859789ab
Feed Name: The Hacker News
**Cisco released patches for CVE-2024-20272**, a critical arbitrary file upload vulnerability in the Unity Connection web interface (CVSS 7.3) that could allow attackers to store malicious files, execute arbitrary OS commands, and gain root privileges; fixes are provided for affected 12.5 and 14.x builds (version 15 is not vulnerable). The advisory credits the researcher, reports no observed exploitation in the wild, and also notes updates for multiple medium-severity issues while declining to patch an EoL WAP371 command-injection bug (CVE-2024-20287).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
