cbcvebase.
CVE-2024-20253
published 2024-01-26

CVE-2024-20253: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute…

PriorityP178critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
2.06%
79.2th percentile
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.

Affected

273 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_packaged_contact_center_enterprise
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager

Detection & IOCsextracted from sources · hover to see the quote

  • Detect exploitation attempts by monitoring for crafted messages sent to listening ports on Cisco Unified Communications and Contact Center Solutions products — the attack vector is a specially crafted message to a listening port triggering Java deserialization (CWE-502).
  • The vulnerability is rooted in Java deserialization (CWE-502); monitor for anomalous Java deserialization payloads arriving on Cisco UC listening ports. Cisco bug IDs CSCwd64245, CSCwd64276, and CSCwd64292 are associated with this issue and can be used to cross-reference patch/log telemetry.
  • Implement ACLs on intermediary devices separating Cisco Unified Communications or Cisco Contact Center Solutions clusters from users and the rest of the network, allowing access only to ports of deployed services — use this as a detection boundary/chokepoint to alert on unexpected port access attempts.
  • ·All affected products are vulnerable in their DEFAULT configurations — no special misconfiguration is required for exploitation.
  • ·Successful exploitation grants command execution as the web services user AND can be leveraged to establish root access on the underlying OS — scope of compromise is full system.
  • ·No workarounds exist that fully address the vulnerability; ACLs are only a mitigation, not a fix. Patches must be applied.
  • ·At time of advisory publication, Cisco was not aware of public exploit code or active malicious exploitation in the wild.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vendor_cisco9.9CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.