Jan. 11, 2024, 2:40 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Cisco has resolved a high-severity security vulnerability in Unity Connection that opens the door for unauthenticated attackers to upload malicious files, execute arbitrary commands, and gain root privileges on affected devices.


Details of the Cisco Unity Connection Vulnerability (CVE-2024-20272)


Tracked as CVE-2024-20272, the vulnerability holds a CVSS score of 7.3, although it is categorized with critical severity by Cisco. Importantly, it is non-local, necessitating neither authentication nor privileges, nor user interaction.


Cisco’s advisory attributes the vulnerability to a …

attackers cisco cve cvss cvss score devices door enable files high malicious privileges root score security security vulnerability severity unauthenticated unity unity connection upload vulnerability

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Application Security Engineer - Enterprise Engineering

@ Meta | Bellevue, WA | Seattle, WA | New York City | Fremont, CA

Security Engineer

@ Retool | San Francisco, CA

Senior Product Security Analyst

@ Boeing | USA - Seattle, WA

Junior Governance, Risk and Compliance (GRC) and Operations Support Analyst

@ McKenzie Intelligence Services | United Kingdom - Remote

GRC Integrity Program Manager

@ Meta | Bellevue, WA | Menlo Park, CA | Washington, DC | New York City