Article Details

Original Article Text

Click to Toggle View

Cisco warns of critical RCE flaw in communications software. Cisco is warning that several of its Unified Communications Manager (CM) and Contact Center Solutions products are vulnerable to a critical severity remote code execution security issue. Cisco's Unified Communications and Contact Center Solutions are integrated solutions that provide enterprise-level voice, video, and messaging services, as well as customer engagement and management. The company has published a security bulletin to warn about the vulnerability, currently tracked as CVE-2024-20253, which could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability was discovered by Synacktiv researcher Julien Egloff and received a 9.9 base score out of a maximum of 10. It is caused by improper processing of user-provided data read into memory. Attackers could exploit it by sending a specially crafted message to a listening port, potentially gaining the ability to execute arbitrary commands with the privileges of the web services user, and establish root access. CVE-2024-20253 impacts the following Cisco products in their default configurations: The vendor says there is no workaround and the recommended action is to apply the available security updates. The following releases address the critical remote code execution (RCE) flaw: Cisco advises admins to set up access control lists (ACLs) as a mitigation strategy for case where applying the updates is not immediately possible. Specifically, users are recommended to implement ACLs on intermediary devices that separate the Cisco Unified Communications or Cisco Contact Center Solutions cluster from users and the rest of the network. The ACLs must be configured to allow access only to the ports of deployed services, effectively controlling the traffic that can reach the affected components. Before deploying any mitigation measures, admins should evaluate their applicability and potential impact on the environment, and test them in a controlled space to ensure business operations are not impacted. The company notes that it is not aware of any public announcements or malicious use of the vulnerability.

Daily Brief Summary

CYBERCRIME // Cisco Issues Alert for Critical Security Flaw in Communication Products

Cisco has issued a security advisory for a critical remote code execution (RCE) vulnerability affecting several of its Unified Communications Manager and Contact Center Solutions products.

The vulnerability, assigned CVE-2024-20253, could allow an unauthenticated, remote attacker to execute arbitrary code on an impacted system.

Discovered by Synacktiv researcher Julien Egloff, the severity of the flaw is rated 9.9 out of 10, indicating a critical level of potential impact.

Attackers could exploit the flaw by sending a specially crafted message to a listening port on vulnerable devices, potentially gaining command execution with root access.

Affected products are at risk in their default configurations, and Cisco has made security updates available as there is no alternative workaround.

Cisco advises administrators to set up access control lists (ACLs) to restrict access to affected components until updates can be applied.

The company has shared detailed guidance on implementing ACLs and cautions admins to assess, test, and understand the implications of mitigation before deployment to avoid business disruption.

There have been no reports of public announcements or malicious exploitation of the vulnerability as of the issuance of the advisory.