CVE-2024-20253

Severity
10.0CRITICAL
EPSS
3.0%
top 13.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 26

Description

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the u

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:HExploitability: 3.9 | Impact: 5.3

Affected Packages13 packages

🔴Vulnerability Details

2
GHSA
GHSA-gxh9-cf3g-3v7f: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exec2024-01-26
CVEList
CVE-2024-20253: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to exec2024-01-26

📋Vendor Advisories

1
Cisco
Cisco Unified Communications Products Remote Code Execution Vulnerability2024-01-24
CVE-2024-20253 (CRITICAL CVSS 10) | A vulnerability in multiple Cisco U | cvebase.io