
Cisco has released security patches to address a critical vulnerability, impacting multiple Unified Communications and Contact Center Solutions products.
The vulnerability tracked as CVE-2024-20253 with a CVSS Score of 9.9 is unauthenticated one and a remote attacker can exploit the flaw to execute arbitrary code on an affected device.
The root cause of the issue is the improper processing of user-provided data that is being read into memory. An attacker can exploit the flaw by sending a crafted message to a listening port of an unpatched device.
The vulnerability impacts the following products in the default configuration:
- Unified Communications Manager (Unified CM) (CSCwd64245)
- Unified Communications Manager IM & Presence Service (Unified CM IM&P) (CSCwd64276)
- Unified Communications Manager Session Management Edition (Unified CM SME) (CSCwd64245)
- Unified Contact Center Express (UCCX) (CSCwe18773)
- Unity Connection (CSCwd64292)
- Virtualized Voice Browser (VVB) (CSCwe18840)
There are no workarounds to fix the issue. To mitigate is to establish an access control lists (ACLs) on intermediary devices that separate the Cisco Unified Communications or Cisco Contact Center Solutions cluster from users and the rest of the network to allow access only to the ports of deployed services.
The Cisco PSIRT is not aware of attacks in the wild exploiting this flaw.