Critical Cisco product flaw allows remote hack

CALIFORNIA, UNITED STATES — Tech giant Cisco recently disclosed a high-severity vulnerability in several unified communication and contact center products. The flaw, tracked as CVE-2024-20253, carries a severity score of 9.9/10.
In a recent security advisory, Cisco said that the flaw allows an unauthenticated, remote attacker to execute arbitrary commands by sending specially crafted messages to listening ports.
Successful exploitation provides the attacker operating system-level access with the privileges of the web services account. The attacker could then potentially gain root access to the device via malware.
Affected software includes Cisco’s Unified Communications Manager (Unified CM), Unified CM IM & Presence Service, Unified CM Session Management Edition, Unified Contact Center Express (UCCX), Unity Connection, and Virtualized Voice Browser (VVB).
Cisco warned that there is no workaround available for the vulnerability. However, they had already released patches for the vulnerability and urged customers to update immediately.
Cisco’s Product Security Incident Response Team stated that, as of now, they do not know any public disclosures or exploitation of the vulnerability outlined in their advisory.
Related news
- Cisco cuts 4,000 jobs amid sales slowdown · 19 Feb
- Cognigy launches AI Copilot to enhance contact centers · 22 Nov 2023
- PH considers dubbing ban to preserve BPO supremacy · 29 Feb
Disclosure: Outsource Accelerator uses AI tools in the backend of its editorial workflow. Every article is reviewed and verified by a human editor before publication.
Stay ahead of the outsourcing industry. Join thousands of business leaders who rely on Outsource Accelerator for the news, trends, and expert insights that matter. Subscribe to our free newsletter and never miss an update.

Independent




