CVE-2024-20253
Public exploit available. Not confirmed exploited in the wild yet. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
Steps
Written by AI from the record- Check whether you run any of these Cisco products: cisco unified communications manager (or unified communications manager), cisco unity connection, cisco unified communications manager im and presence service, cisco unified contact center enterprise (or packaged enterprise), cisco unified contact center express, cisco virtualized voice browser.
- Check your currently installed software version for each affected product you operate.
- Upgrade unified communications manager, unified communications manager im and presence service, and unity connection to 12.5(1)su8 (this is the fixed version).
- If you can’t patch immediately, immediately restrict external access to the management/communication interfaces for these systems (allow only trusted networks) until upgrades are complete.
- After upgrading, review logs and alerts for signs of unexpected file creation and suspicious payload activity, and confirm the system services still start and operate normally.
What it is
From the CVE record
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
In plain language
Written by AI from the recordThis Cisco phone/voice and call-center software has a remote “break-in” flaw that lets attackers run commands without logging in; if your business runs an affected Cisco product, you should treat it as urgent to patch.
CVE-2024-20253 is an unauthenticated remote command execution flaw (CWE-502) in Cisco Unified Communications/Contact Center products, triggered by sending a specially crafted network message to an exposed listening interface; exploitation has been reported and is actively being used to plant payloads (e.g., file:// payloads).
If you're affected
- Full device compromise
- Root access possible
- Service outage risk
- Business email/voice disruption
- Customer communications disruption
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Not in the catalog. CISA has not confirmed exploitation.
- Public exploits
0 sources with a proof of concept or module.
Exploit links, PoCs and Metasploit modules after sign-in- EPSS
2.4% chance of exploitation activity in the next 30 days, which ranks it in the 83rd percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
6 events over 881 days, from the signal feeds we watch.
- OpenVAS check added
- Patch availablerecord updated
- Publishedweakness classified, att&ck mapped
Affected products
- Cisco Unified Contact Center EnterpriseNetworking Infrastructure
- Cisco Unity ConnectionNetworking Infrastructure
- Cisco Unified Communications ManagerNetworking Infrastructure
- Cisco Unified Contact Center ExpressNetworking Infrastructure
- Cisco Unified Communications Manager IM and Presence ServiceNetworking Infrastructure
- Cisco Virtualized Voice BrowserNetworking Infrastructure
- Cisco Packaged Contact Center EnterpriseNetworking Infrastructure
- Cisco Unified Communications Manager / Cisco Unity ConnectionNetworking Infrastructure
And 13 more affected products. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H
Scored 9.9 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity LowNo special conditions — the attack can be reliably reproduced
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope ChangedThe exploit can affect other components (e.g. sandbox escape, host compromise from VM)
Impact if exploited
- Confidentiality LowSome restricted information is disclosed, but limited in scope
- Integrity LowData modification is possible but limited in scope or consequence
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
Sources
References in the record
In the news
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next serious one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for Cisco, not every advisory. This one: public exploit.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI