Skip to content
TopicTracker
From HackerNewsView original
TranslationTranslation

Cisco confirms attackers exploiting Unified CM flaw

Cisco confirmed that attackers are actively exploiting a security flaw in Unified Communications Manager (Unified CM). The vulnerability, tracked as CVE-2024-20253, allows remote attackers to execute arbitrary code without authentication. Cisco urged customers to apply available patches immediately to mitigate the threat.

Background

Cisco Unified Communications Manager (Unified CM, formerly CallManager) is the call-routing and phone-system brain used by large enterprises and government agencies — essentially the PBX (private branch exchange) for VoIP-based office telephony. A remote code execution (RCE) flaw means an unauthenticated attacker on the same network could send a maliciously crafted request and take over the system without a password. The vulnerability (CVE-2025-20124) was disclosed in late 2024 along with a patch, but exploitation in the wild has now been confirmed. Cisco's belated confirmation is significant because Unified CM systems often sit at the boundary of internal voice and data networks, giving a foothold for lateral movement into sensitive IT environments. Attackers typically exploit such flaws to deploy ransomware, steal credentials, or eavesdrop on communications.

Related stories