cbcvebase.
CVE-2024-20272
published 2024-01-17

CVE-2024-20272: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an…

PriorityP273critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.60%
73.0th percentile
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system and execute commands on the underlying operating system. This vulnerability is due to a lack of authentication in a specific API and improper validation of user-supplied data. An attacker could exploit this vulnerability by uploading arbitrary files to an affected system. A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system, and elevate privileges to root.

Affected

23 ranges
VendorProductVersion rangeFixed in
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscocisco_unity_connection
ciscounity_connection< 12.5.1.19017-412.5.1.19017-4
ciscounity_connection>= 14.0 < 14.0.1.14006-514.0.1.14006-5
ciscounity_connection_unauthenticated

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit targets a specific unauthenticated API endpoint in the Cisco Unity Connection web-based management interface — monitor for unauthenticated file upload requests to the management interface API
  • Monitor for unexpected file creation followed by OS command execution and privilege escalation to root on Cisco Unity Connection systems
  • Affected versions are Cisco Unity Connection 12.5 and earlier (patched: 12.5.1.19017-4) and version 14 (patched: 14.0.1.14006-5); version 15 is not vulnerable — use version detection to identify unpatched assets
  • ·No public proof-of-concept exploit or active in-the-wild exploitation was observed at time of disclosure, reducing immediate risk but not eliminating it
  • ·There are no workarounds available; patching is the only remediation
  • ·The vulnerability is tracked under Cisco Bug ID CSCwh14380

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.