Cisco has patched Unity Connection with software upgrades to fix a serious security vulnerability that might allow an attacker to run arbitrary instructions on the underlying system.
The vulnerability, identified as CVE-2024-20272 (CVSS score: 7.3), is an arbitrary file upload flaw that exists in the web-based administration interface. It is caused by incorrect user-supplied data validation and a lack of authentication in a particular API.
In a warning published on Wednesday, Cisco stated that “an attacker could exploit this vulnerability by uploading arbitrary files to an affected system.” “A successful exploit could allow the attacker to store malicious files on the system, execute arbitrary commands on the operating system read more Cisco Fixes High-Risk Vulnerability Impacting Unity Connection Software.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
