PT-2025-29853 · Cisco · Cisco Unified Intelligence Center

Abdelrahman Osama

+1

·

Published

2025-07-16

·

Updated

2025-07-22

·

CVE-2025-20274

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cisco Unified Intelligence Center (affected versions not specified)
Description A vulnerability exists in the web-based management interface of Cisco Unified Intelligence Center that could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This issue is due to improper validation of files uploaded through the interface. Successful exploitation could allow an attacker to store malicious files on the system and execute arbitrary commands on the operating system, potentially leading to root-level access. The security impact is considered high due to the potential for privilege escalation. To exploit this vulnerability, an attacker must possess valid credentials for a user account with at least the role of Report Designer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2025-09600
CVE-2025-20274

Affected Products

Cisco Unified Intelligence Center