Back to overview

CVE-2024-20253

CRITICAL
9.9
CVSS 3.1
Description
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.

Metadata

CVE ID
CVE-2024-20253
State
PUBLISHED
Assigner
cisco
Reserved
2023-11-08 15:08 UTC
Published
2024-01-26 17:28 UTC
Last updated
2025-05-29 15:12 UTC
Primary CWE
CWE-502
Deserialization of Untrusted Data
Vendor / Product
Cisco / Cisco Unified Contact Center Enterprise
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
partial
Affected products (8)
VendorProductPlatformVersions
Cisco Cisco Packaged Contact Center Enterprise 10.5(1), 10.5(2), 10.5(1)_ES7, 10.5(2)_ES8 …
Cisco Cisco Unified Communications Manager 12.0(1)SU1, 12.0(1)SU2, 12.0(1)SU3, 12.0(1)SU4 …
Cisco Cisco Unified Communications Manager / Cisco Unity Connection 10.5(2)SU10, 10.5(1), 10.5(1)SU1, 10.5(1)SU1a …
Cisco Cisco Unified Communications Manager IM and Presence Service 10.5(1), 10.5(2), 10.5(2a), 10.5(2b) …
Cisco Cisco Unified Contact Center Enterprise N/A
Cisco Cisco Unified Contact Center Express 8.5(1), 9.0(2)SU3ES04, 10.0(1)SU1, 10.0(1)SU1ES04 …
Cisco Cisco Unity Connection 12.0(1)SU1, 12.0(1)SU2, 12.0(1)SU3, 12.0(1)SU4 …
Cisco Cisco Virtualized Voice Browser 11.0(1), 11.5(1), 11.5(1)ES29, 11.5(1)ES32 …
Weakness (CWE)
CWESourceDescription
CWE-502 cna Deserialization of Untrusted Data
CWE-502 adp CWE-502 Deserialization of Untrusted Data
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Back to overview