TCP: Cisco Unified Communications Products Remote Code Execution

This signature detects attempts to exploit a known vulnerability against Cisco Unified Communications Products. A successful attack can lead to arbitrary code execution.

Extended Description

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.

Affected Products

Cisco virtualized_voice_browser

References

CVE: CVE-2024-20253

Short Name
TCP:C2S:CISCO-UNIFIED-CMNTN-RCE
Severity
Major
Recommended
False
Recommended Action
Drop
Category
TCP
Keywords
CVE-2024-20253 Cisco Code Communications Execution Products Remote Unified
Release Date
02/21/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3680
Port
TCP/41160
False Positive
Unknown
Vendors

Cisco

Found a potential security threat?