NA

CVE-2024-20253

Published: 26/01/2024 Updated: 02/02/2024
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote malicious user to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the malicious user to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cisco unified communications manager

cisco unified communications manager im and presence service

cisco unity connection

cisco unified contact center express 12.5\\(1\\)

cisco virtualized voice browser 12.6\\(2\\)

cisco virtualized voice browser 12.6\\(1\\)

cisco virtualized voice browser 12.5\\(1\\)

Vendor Advisories

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device This vulnerability is due to the improper processing of user-provided data that is being read into memory An attacker could exploit this vulnerability by sen ...