A critical vulnerability, identified as CVE-2024-20253, has been discovered in multiple Cisco Unified Communications and Contact Center Solutions products. This flaw allows unauthenticated remote attackers to execute arbitrary code on affected devices, posing a high-risk threat to system integrity and security.
The vulnerability stems from insecure input validation during the deserialization of untrusted data. An attacker can exploit this flaw by sending a specially crafted message to a listening port on the affected device. Successful exploitation may lead to the execution of arbitrary code, resulting in a complete compromise of the vulnerable system.
This vulnerability affects several Cisco products in their default configuration, including but not limited to:
Vulnerable software versions include Cisco Packaged Contact Center Enterprise 12.0.0 - 12.5.2, Cisco Unified Communications Manager 11.5(1) - 14SU4, and others.
To mitigate this vulnerability, it is recommended to install updates from the vendor's website. Furthermore, Cisco advises implementing access control lists (ACLs) on intermediary devices to separate the Cisco Unified Communications or Cisco Contact Center Solutions cluster from users and the rest of the network, allowing access only to the ports of deployed services.