CyberzSOC

Publication detail
← Back to advisories & guidance

2024-070: Critical Vulnerabilities in Cisco Products ↗ source

July 18, 2024 CERT-EU Advisory

Summary

It is strongly recommended applying update on affected devices as soon as possible, prioritising internet facing and business critical devices. The critical vulnerability CVE-2024-20401, with a CVSS score of 9.8, is an arbitrary file write flaw [1]. It affects the content scanning and message filtering features of Cisco Secure Email Gateway and is due to improper handling of email attachments when file analysis and content filters are enabled. A successful exploit could allow the attacker to replace any file on the underlying file system. The attacker could then perform any of the following actions: add users with root privileges, modify the device configuration, execute arbitrary code, or cause a permanent denial of service (DoS) condition on the affected device.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-20419 10.0 Critical Cisco Cisco Smart Software Manager On-Prem A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to…
CVE-2024-20401 9.8 Critical Cisco Cisco Secure Email A vulnerability in the content scanning and message filtering features of Cisco Secure Email Gateway could allow an unauthenticated, remote attacker …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.