PT-2025-45133 · Cisco · Cisco Unified Contact Center Express
Published
2025-11-05
·
Updated
2025-11-05
·
CVE-2025-20376
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Cisco Unified Contact Center Express (Unified CCX) (affected versions not specified)
Description
A flaw exists in the web interface of Cisco Unified CCX that may allow a remote attacker with valid administrative credentials to upload and execute arbitrary files. This is due to inadequate input validation related to file upload mechanisms. Successful exploitation could enable the attacker to execute commands on the system and gain root-level privileges. The vulnerability involves unrestricted file uploads of malicious types.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cisco Unified Contact Center Express