cve/2024/CVE-2024-20253.md
2025-09-29 21:09:30 +02:00

209 lines
19 KiB
Markdown

### [CVE-2024-20253](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-20253)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Packaged%20Contact%20Center%20Enterprise&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unified%20Communications%20Manager%20%2F%20Cisco%20Unity%20Connection&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unified%20Communications%20Manager%20IM%20and%20Presence%20Service&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unified%20Communications%20Manager&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unified%20Contact%20Center%20Enterprise&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unified%20Contact%20Center%20Express&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Unity%20Connection&color=blue)
![](https://img.shields.io/static/v1?label=Product&message=Cisco%20Virtualized%20Voice%20Browser&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=10.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.0(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.0(1)SU1ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.0(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)SU1ES10%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)SU1a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(1)_ES7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU10%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU2a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU3a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU4a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU6a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)SU9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2)_ES8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2a)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.5(2b)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU2ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU3ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU3ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=10.6(1)SU3ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1)SU1ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1)SU1ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)SU3a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(1a)SU4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0.1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0.2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.0.5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES27%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES29%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES32%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES36%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)ES43%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU10%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU11%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU1ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU1ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU1ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU3a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU3b%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU5a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU8%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)SU9%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES27%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES29%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES32%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES36%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES43%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES53%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.5(1)_ES54%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES22%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES80%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES81%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES82%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES83%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES84%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES85%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES86%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES87%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(1)_ES88%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES05%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES06%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES07%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=11.6(2)ES08%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SU4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)SU5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES05%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES06%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES07%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.0(1)_ES08%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU3%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU4%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU5%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU6%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU7%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)SU7a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES06%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES07%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES08%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES09%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES10%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES11%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES12%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES14%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_ES15%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU01_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU01_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU01_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU02_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU02_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU02_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU02_ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU03_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU03_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU03_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU03_ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(1)_SU_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.5(2)_ET%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES05%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES06%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES07%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES08%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(1)_ES09%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(2)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(2)_ES01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(2)_ES02%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(2)_ES03%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=12.6(2)_ET01%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14SU1%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14SU2%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=14SU2a%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=8.5(1)%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=9.0(2)SU3ES04%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=N%2FA%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Deserialization%20of%20Untrusted%20Data&color=brightgreen)
### Description
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
### POC
#### Reference
No PoCs from references.
#### Github
- https://github.com/EfstratiosLontzetidis/blogs_advisories_reports_papers