Security News > 2024 > January > Cisco says critical Unity Connection bug lets attackers get root

Cisco says critical Unity Connection bug lets attackers get root
2024-01-10 20:42

Cisco has patched a critical Unity Connection security flaw that can let unauthenticated attackers remotely gain root privileges on unpatched devices.

Unity Connection is a fully virtualized messaging and voicemail solution for email inboxes, web browsers, Cisco Jabber, Cisco Unified IP Phone, smartphones, or tablets with high availability and redundancy support.

Today, Cisco also patched ten medium-severity security vulnerabilities in multiple products, allowing attackers to escalate privileges, launch cross-site scripting attacks, inject commands, and more.

Although attackers could exploit this bug to execute arbitrary commands with root privileges on unpatched devices, administrative credentials are also required for successful exploitation.

Cisco says it will not release firmware updates to patch the CVE-2024-20287 security flaw because the Cisco WAP371 device reached end-of-life in June 2019.

In October, Cisco also patched two zero-days exploited to hack over 50,000 IOS XE devices within a single week.


News URL

https://www.bleepingcomputer.com/news/security/cisco-says-critical-unity-connection-bug-lets-attackers-get-root/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-01-17 CVE-2024-20287 Command Injection vulnerability in Cisco Wap371 Firmware
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-77
7.2

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Cisco 4409 230 3101 1852 602 5785