Cisco patches more critical security bugs — here's how you can stay protected

A computer being guarded by cybersecurity.
(Image credit: iStock)

Cisco has released a patch for multiple vulnerabilities found in the Expressway Series collaboration gateways. 

Given that two of them are rated as “critical”, and would allow threat actors to execute arbitrary code remotely, patching the flaws without delay is recommended.

As per the advisory published together with the patch, Cisco addressed CVE-2024-20252, and CVE-2024-20254, which could be abused by tricking a victim into clicking a custom-tailored link. Should the victim also happen to be an administrator, this would grant the attackers the ability to add new user accounts, run arbitrary code, elevate privileges, and more. The attack is described as a “cross-site request forgery (CSRF)”.

No PoC or evidence of exploits

"An attacker could exploit these vulnerabilities by persuading a user of the API to follow a crafted link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user," Cisco said in its advisory. 

"If the affected user has administrative privileges, these actions could include modifying the system configuration and creating new privileged accounts."

Besides the two above mentioned flaws, Cisco also fixed CVE-2024-20255, which could have been used by the attackers to change system configuration and run denial of service attacks. This flaw, together with CVE-2024-20254, can only be abused on Expressway Series instances with default configurations, Cisco further explained, while for the first one, the victim needs to have the cluster database (CDB) API feature toggled on.

The company also stressed that the patches are for Expressway Series, and not TelePresence Video Communication Server (VCS) gateway which, since it reached end-of-life last year, will not be getting a patch at all. 

The good news is that Cisco found no evidence of hackers already abusing these flaws in their campaigns. There are no proof-of-concepts (PoC) out there, either.

Via BleepingComputer 

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Cisco patches critical security issues, so update now
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
The best free firewall
Palo Alto warns another major firewall hack has been detected
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 23 (game #385)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 23 (game #651)
Google Pixel 9 Pro Fold main display opened
Apple is rumored to be prioritizing battery life on the foldable iPhone – which could also feature a liquid metal hinge for added durability
Google Pixel 9
The Google Pixel 10 just showed up in Android code – and may come with a useful speed boost
L-mount alliance
Sirui joins L-Mount Alliance to deliver its superb budget lenses for Leica, DJI, Sigma and Panasonic cameras