Cisco has fixed a critical vulnerability that allows attackers to add new users with root privileges and crash Security Email Gateway (SEG) appliances. It all starts with sending emails with malicious attachments.

The vulnerability is tracked as CVE-2024-20401 and is located in the content scanning and message of SEG devices. It is caused by a path traversal weakness that allows the replacement of any file in the underlying operating system.
“ This vulnerability is due to improper handling of email attachmentswhen file analysis and content filters are enabled. A successful exploit could allow an attacker to overwrite any file in the underlying system file ,” Cisco explained . “ The attacker could then perform any of the following actions: add users with root privileges, modify the device configuration, execute code, or cause a denial of service (DoS) condition on the affected device.”
See also: Cisco SSM On-Prem bug allows password change
The CVE-2024-20401 vulnerability affects SEG devices if they are running a vulnerable version of Cisco AsyncOS and if the following conditions are met:
- The file analysis feature (part of Cisco Advanced Malware Protection) or content filtering feature is enabled and assigned to an incoming mail policy.
- The version of Content Scanner Tools is older than 23.3.0.4823
Cisco has fixed this vulnerability in Content Scanner Tools 23.3.0.4823 and later. The update is included by default in Cisco AsyncOS for Cisco Secure Email Software versions 15.5.1-055 and later.

How to find vulnerable devices
To determine if file analysis is enabled, log in to the product's web management interface and navigate to Mail Policies > Incoming Mail Policies > Advanced Malware Protection > Mail Policy. There, check if “ Enable File Analysis ” is selected.
See also: Cisco fixes zero-day vulnerability in NX-OS
To determine if content filters are enabled , open the product's web interface, go to “Choose Mail Policies > Incoming Mail Policies > Content Filters” and check if the “ Content Filters ” column is enabled.
Vulnerable Cisco SEG devices are being taken offline after successful exploits of the CVE-2024-20401 vulnerability, but the company advises customers to contact the Technical Assistance Center (TAC) to bring them back online.
Cisco advised all administrators to update vulnerable devices to protect them.
See also: Cisco: Fixed Webex vulnerabilities used for German government surveillance
The discovery and immediate patching of vulnerabilities like CVE-2021-1609 underscores the importance of regularly updating software and devices to protect against potential cyberattacks. Organizations should also have a robust security in place to respond quickly and mitigate any vulnerabilities discovered. By remaining vigilant and implementing the necessary protections, organizations can ensure the security of their systems and data.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
