Cisco ECE Security Update Advisory (CVE-2024-20484)
Overview
Cisco has released a security update that addresses a vulnerability in Cisco Enterprise Chat and Email. Users of affected products are advised to update to the latest version.
Affected Products
CVE-2024-20484
- Cisco ECE Version: ~12.5 (inclusive)
- Cisco ECE version: 12.6
Resolved Vulnerabilities
Vulnerability due to insufficient validation of Media Routing Peripheral Interface Manager (MR PIM) traffic (CVE-2024-20484)
Vulnerability Patches
Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-20484
- Cisco ECE Version: 12.5(1) ES9
- Cisco ECE Version: 12.6(1) ES9 ET3
References
[1] Cisco Enterprise Chat and Email Denial of Service Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-dos-Oqb9uFEv