Cisco ECE Security Update Advisory (CVE-2024-20484)

Overview

Cisco has released a security update that addresses a vulnerability in Cisco Enterprise Chat and Email. Users of affected products are advised to update to the latest version.

Affected Products

CVE-2024-20484

  • Cisco ECE Version: ~12.5 (inclusive)
  • Cisco ECE version: 12.6

 

 

Resolved Vulnerabilities

Vulnerability due to insufficient validation of Media Routing Peripheral Interface Manager (MR PIM) traffic (CVE-2024-20484)

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

CVE-2024-20484
 

  • Cisco ECE Version: 12.5(1) ES9
  • Cisco ECE Version: 12.6(1) ES9 ET3

 

References

[1] Cisco Enterprise Chat and Email Denial of Service Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-dos-Oqb9uFEv