PT-2025-22376 · Cisco+1 · Cisco Unified Communications/Contact Center Solutions+1
Published
2025-05-21
·
Updated
2025-05-21
·
CVE-2025-20112
CVSS v2.0
5.2
Medium
| Vector | AV:L/AC:L/Au:S/C:P/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications and Contact Center Solutions products (affected versions not specified)
Description
A vulnerability in the system could allow an authenticated, local attacker to elevate privileges to root on an affected device. This issue is due to excessive permissions assigned to system commands. An attacker could exploit this by executing crafted commands on the underlying operating system, potentially allowing them to escape the restricted shell and gain root privileges. To exploit this, an attacker would need administrative access to the ESXi hypervisor.
Recommendations
To resolve the issue, apply the necessary patches or updates to the affected Cisco Unified Communications and Contact Center Solutions products.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Communications/Contact Center Solutions
Esxi