Kritischer Cisco-Fehler ermöglicht Hackern das Hinzufügen von Root-Benutzern auf SEG-Geräten

Teilen:

Cisco has fixed a critical severity vulnerability that lets attackers add new users with root privileges and permanently crash Security Email Gateway (SEG) appliances using emails with malicious attachments.

Tracked as CVE-2024-20401, this arbitrary file write security flaw in the SEG content scanning and message filtering features is caused by an absolute path traversal weakness that allows replacing any file on the underlying operating system.

“This vulnerability is due to improper handling of email attachments when file analysis and content filters are enabled. A successful exploit could allow the attacker to replace any file on the underlying file system,” Cisco explained.

“The attacker could then perform any of the following actions: add users with root privileges, modify the device configuration, execute arbitrary code, or cause a permanent denial of service (DoS) condition on the affected device.”

CVE-2024-20401 impacts SEG appliances if they’re running a vulnerable Cisco AsyncOS release and the following conditions are met:

  • The file analysis feature (part of Cisco Advanced Malware Protection) or the content filter feature is enabled and assigned to an incoming mail policy.
  • The Content Scanner Tools version is earlier than 23.3.0.4823

The fix for this vulnerability is delivered to affected devices with the Content Scanner Tools package versions 23.3.0.4823 and later. The updated version is included by default in Cisco AsyncOS for Cisco Secure Email Software releases 15.5.1-055 and later.

How to find vulnerable appliances

To determine whether file analysis is enabled, connect to the product web management interface, go to “Mail Policies > Incoming Mail Policies > Advanced Malware Protection > Mail Policy,” and check if “Enable File Analysis” is checked.

To find if content filters are enabled, open the product web interface and check if the “Content Filters” column under “Choose Mail Policies > Incoming Mail Policies > Content Filters” contains anything other than Disabled.

While vulnerable SEG appliances are permanently taken offline following successful CVE-2024-20401 attacks, Cisco advises customers to contact its Technical Assistance Center (TAC) to bring them back online, which will require manual intervention.

Cisco added that no workarounds are available for appliances impacted by this security flaw, and it advised all admins to update vulnerable appliances to secure them against attacks.

The company’s Product Security Incident Response Team (PSIRT) has not found evidence of public proof of concept exploits or exploitation attempts targeting the CVE-2024-20401 vulnerability.

On Wednesday, Cisco also fixed a maximum severity bug that lets attackers change any user password on unpatched Cisco Smart Software Manager On-Prem (Cisco SSM On-Prem) license servers, including administrators.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:09 am, Juni 23, 2025
Wetter-Symbol 18°C
L: 17° | H: 18°
broken clouds
Luftfeuchtigkeit: 78 %
Druck: 1010 mb
Wind: 15 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 18°°C 0.2 mm 20% 14 mph 76 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
13° | 22°°C 0.2 mm 20% 13 mph 80 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 27°°C 0 mm 0% 9 mph 86 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
18° | 26°°C 0.48 mm 48% 14 mph 84 % 1016 mb 0 mm/h
Fr. Juni 27 10:00 pm
Wetter-Symbol
17° | 28°°C 0 mm 0% 16 mph 72 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
16° | 17°°C 0.2 mm 20% 13 mph 76 % 1011 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 12 mph 54 % 1013 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 12 mph 34 % 1014 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 32 % 1014 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
22° | 22°°C 0 mm 0% 13 mph 39 % 1014 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 10 mph 53 % 1016 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 69 % 1016 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€88,162.20
-1.05%
Ethereum(ETH)
€1,949.66
-1.17%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.76
-1.97%
Solana(SOL)
€115.61
-1.37%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.132766
-1.07%
Shiba Inu(SHIB)
€0.000010
-1.51%
Pepe(PEPE)
€0.000008
-4.03%
Peanut das Eichhörnchen(PNUT)
€0.218896
13.10%
Nach oben scrollen