PT-2025-27659 · Cisco · Cisco Unified Communications Manager Session Management Edition+1
Published
2025-07-02
·
Updated
2026-05-25
·
CVE-2025-20309
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Communications Manager (Unified CM) versions 15.0.1.13010-1 through 15.0.1.13017-1
Cisco Unified Communications Manager Session Management Edition (Unified CM SME) versions 15.0.1.13010-1 through 15.0.1.13017-1
Description
A vulnerability exists in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) that could allow an unauthenticated, remote attacker to log in to an affected device using the root account. This is due to the presence of static, hardcoded credentials for the root account, which were reserved for development purposes and cannot be modified or deleted. Successful exploitation could grant the attacker root access and the ability to execute arbitrary commands on the system. This vulnerability is actively exploited.
Recommendations
Update Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) to version 15SU3 or apply the CSCwp27755 patch immediately.
Fix
RCE
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Communications Manager
Cisco Unified Communications Manager Session Management Edition