Vulnerability Details CVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 77.5%
CVSS Severity
CVSS v3 Score 9.9
Products affected by CVE-2024-20253
-
cpe:2.3:a:cisco:unified_communications_manager:-
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su1
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su10
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su2
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su2a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su3
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su3a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su4
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su4a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su6
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su6a
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su7
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su8
-
cpe:2.3:a:cisco:unified_communications_manager:10.5(2)su9
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su11
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su5
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su7
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su8
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1)su9
-
cpe:2.3:a:cisco:unified_communications_manager:11.5(1.10000.6)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager:12.0(1.10000.10)
-
cpe:2.3:a:cisco:unified_communications_manager:12.5
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su1
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su2
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su3
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su5
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su6
-
cpe:2.3:a:cisco:unified_communications_manager:12.5(1)su7
-
cpe:2.3:a:cisco:unified_communications_manager:14.0
-
cpe:2.3:a:cisco:unified_communications_manager:14.0(1.10000.20)
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su1
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su2
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su2a
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su3
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su4
-
cpe:2.3:a:cisco:unified_communications_manager:14.0su4a
-
cpe:2.3:a:cisco:unified_communications_manager:14su1
-
cpe:2.3:a:cisco:unified_communications_manager:14su2
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:-
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(2)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:10.5(2)su10
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)su11
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)su8
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:11.5(1)su9
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.0
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5(1)su4
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:12.5(1)su6
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0(1)
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:14.0su1
-
cpe:2.3:a:cisco:unified_communications_manager_im_and_presence_service:9.0(1)
-
cpe:2.3:a:cisco:unified_contact_center_express:12.5(1)
-
cpe:2.3:a:cisco:unity_connection:-
-
cpe:2.3:a:cisco:unity_connection:1.1
-
cpe:2.3:a:cisco:unity_connection:1.1(1)
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_es1
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_es12
-
cpe:2.3:a:cisco:unity_connection:1.1(1)_sr1
-
cpe:2.3:a:cisco:unity_connection:1.2
-
cpe:2.3:a:cisco:unity_connection:1.2(1)
-
cpe:2.3:a:cisco:unity_connection:1.2(1)_es65
-
cpe:2.3:a:cisco:unity_connection:1.2(1)sr2
-
cpe:2.3:a:cisco:unity_connection:1.2_base
-
cpe:2.3:a:cisco:unity_connection:10.0.0
-
cpe:2.3:a:cisco:unity_connection:10.0.5
-
cpe:2.3:a:cisco:unity_connection:10.5
-
cpe:2.3:a:cisco:unity_connection:10.5(2)
-
cpe:2.3:a:cisco:unity_connection:10.5(2)su10
-
cpe:2.3:a:cisco:unity_connection:10.5(2.3009)
-
cpe:2.3:a:cisco:unity_connection:10.5_base
-
cpe:2.3:a:cisco:unity_connection:10.5su5
-
cpe:2.3:a:cisco:unity_connection:11.0
-
cpe:2.3:a:cisco:unity_connection:11.0(0.98000.225)
-
cpe:2.3:a:cisco:unity_connection:11.0(0.98000.332)
-
cpe:2.3:a:cisco:unity_connection:11.0_0
-
cpe:2.3:a:cisco:unity_connection:11.5
-
cpe:2.3:a:cisco:unity_connection:11.5(0.199)
-
cpe:2.3:a:cisco:unity_connection:11.5(0.98)
-
cpe:2.3:a:cisco:unity_connection:11.5(1)
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su8
-
cpe:2.3:a:cisco:unity_connection:11.5(1)su9
-
cpe:2.3:a:cisco:unity_connection:11.5(1.10000.6)
-
cpe:2.3:a:cisco:unity_connection:11.5_base
-
cpe:2.3:a:cisco:unity_connection:11.5su7
-
cpe:2.3:a:cisco:unity_connection:12.0
-
cpe:2.3:a:cisco:unity_connection:12.0(1)
-
cpe:2.3:a:cisco:unity_connection:12.0(1)su4
-
cpe:2.3:a:cisco:unity_connection:12.5
-
cpe:2.3:a:cisco:unity_connection:12.5(1)
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su6
-
cpe:2.3:a:cisco:unity_connection:12.5(1)su7
-
cpe:2.3:a:cisco:unity_connection:14.0
-
cpe:2.3:a:cisco:unity_connection:14su1
-
cpe:2.3:a:cisco:unity_connection:14su2
-
cpe:2.3:a:cisco:unity_connection:2.0
-
cpe:2.3:a:cisco:unity_connection:2.0(1)
-
cpe:2.3:a:cisco:unity_connection:2.0_base
-
cpe:2.3:a:cisco:unity_connection:2.1
-
cpe:2.3:a:cisco:unity_connection:2.1(1)
-
cpe:2.3:a:cisco:unity_connection:2.1(2)
-
cpe:2.3:a:cisco:unity_connection:2.1(3)
-
cpe:2.3:a:cisco:unity_connection:2.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(4)
-
cpe:2.3:a:cisco:unity_connection:2.1(4)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(4a)
-
cpe:2.3:a:cisco:unity_connection:2.1(4a)su2
-
cpe:2.3:a:cisco:unity_connection:2.1(5)
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su1
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su2
-
cpe:2.3:a:cisco:unity_connection:2.1(5)su3
-
cpe:2.3:a:cisco:unity_connection:2.1_base
-
cpe:2.3:a:cisco:unity_connection:6.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:7.0
-
cpe:2.3:a:cisco:unity_connection:7.0(2)
-
cpe:2.3:a:cisco:unity_connection:7.0(2a)su2
-
cpe:2.3:a:cisco:unity_connection:7.0(2a)su3
-
cpe:2.3:a:cisco:unity_connection:7.0_base
-
cpe:2.3:a:cisco:unity_connection:7.1
-
cpe:2.3:a:cisco:unity_connection:7.1(1)
-
cpe:2.3:a:cisco:unity_connection:7.1(2)
-
cpe:2.3:a:cisco:unity_connection:7.1(2a)
-
cpe:2.3:a:cisco:unity_connection:7.1(2a)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(2b)
-
cpe:2.3:a:cisco:unity_connection:7.1(2b)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3)
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3a)su1a
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)su1
-
cpe:2.3:a:cisco:unity_connection:7.1(3b)su2
-
cpe:2.3:a:cisco:unity_connection:7.1(5)
-
cpe:2.3:a:cisco:unity_connection:7.1(5)su1a
-
cpe:2.3:a:cisco:unity_connection:7.1(5a)
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su2
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su3
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su4
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su5
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su6
-
cpe:2.3:a:cisco:unity_connection:7.1(5b)su6a
-
cpe:2.3:a:cisco:unity_connection:7.1.5es33.32900-33
-
cpe:2.3:a:cisco:unity_connection:7.1_base
-
cpe:2.3:a:cisco:unity_connection:8.0
-
cpe:2.3:a:cisco:unity_connection:8.0(2c)
-
cpe:2.3:a:cisco:unity_connection:8.0(2c)su1
-
cpe:2.3:a:cisco:unity_connection:8.0(3)
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su1
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su2
-
cpe:2.3:a:cisco:unity_connection:8.0(3a)su3
-
cpe:2.3:a:cisco:unity_connection:8.0_base
-
cpe:2.3:a:cisco:unity_connection:8.5
-
cpe:2.3:a:cisco:unity_connection:8.5(1)
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su1
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su2
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su3
-
cpe:2.3:a:cisco:unity_connection:8.5(1)su6
-
cpe:2.3:a:cisco:unity_connection:8.5_base
-
cpe:2.3:a:cisco:unity_connection:8.6
-
cpe:2.3:a:cisco:unity_connection:8.6(1a)
-
cpe:2.3:a:cisco:unity_connection:8.6(2a)
-
cpe:2.3:a:cisco:unity_connection:8.6.2
-
cpe:2.3:a:cisco:unity_connection:8.6_base
-
cpe:2.3:a:cisco:unity_connection:9.0
-
cpe:2.3:a:cisco:unity_connection:9.1(1)es23
-
cpe:2.3:a:cisco:unity_connection:9.1(1.10)
-
cpe:2.3:a:cisco:unity_connection:9.5
-
cpe:2.3:a:cisco:virtualized_voice_browser:12.5(1)
-
cpe:2.3:a:cisco:virtualized_voice_browser:12.6(1)
-
cpe:2.3:a:cisco:virtualized_voice_browser:12.6(2)