Critical Cisco product flaw allows remote hack

CALIFORNIA, UNITED STATES — Tech giant Cisco recently disclosed a high-severity vulnerability in several unified communication and contact center products. The flaw, tracked as CVE-2024-20253, carries a severity score of 9.9/10.
In a recent security advisory, Cisco said that the flaw allows an unauthenticated, remote attacker to execute arbitrary commands by sending specially crafted messages to listening ports.
Successful exploitation provides the attacker operating system-level access with the privileges of the web services account. The attacker could then potentially gain root access to the device via malware.
Affected software includes Cisco’s Unified Communications Manager (Unified CM), Unified CM IM & Presence Service, Unified CM Session Management Edition, Unified Contact Center Express (UCCX), Unity Connection, and Virtualized Voice Browser (VVB).
Cisco warned that there is no workaround available for the vulnerability. However, they had already released patches for the vulnerability and urged customers to update immediately.
Cisco’s Product Security Incident Response Team stated that, as of now, they do not know any public disclosures or exploitation of the vulnerability outlined in their advisory.