← Back

CVE-2025-20278

nvd nist
Published: Jun 4, 2025Modified: Jul 31, 2025

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.

Affected (193)

8 products
Finesse
Socialminer
Unified Communications Manager
Unified Contact Center Express
Unified Intelligence Center
Unity Connection
Virtualized Voice Browser
Configuration A
81 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.5(1)
Version 10.5(1)_es10
Version 10.5(1)_es1
Version 10.5(1)_es2
Version 10.5(1)_es3
Version 10.5(1)_es4
Version 10.5(1)_es5
Version 10.5(1)_es6
Version 10.5(1)_es7
Version 10.5(1)_es8
Version 10.5(1)_es9
Version 11.0(1)
Version 11.0(1) es1
Version 11.0(1) es2
Version 11.0(1) es3
Version 11.0(1) es4
Version 11.0(1) es5
Version 11.0(1) es6
Version 11.0(1) es7
Version 11.5(1)
Version 11.5(1) es1
Version 11.5(1) es2
Version 11.5(1) es3
Version 11.5(1) es4
Version 11.5(1) es5
Version 11.5(1) es6
Version 11.6(1)
Version 11.6(1) es10
Version 11.6(1) es11
Version 11.6(1) es1
Version 11.6(1) es2
Version 11.6(1) es3
Version 11.6(1) es4
Version 11.6(1) es5
Version 11.6(1) es6
Version 11.6(1) es7
Version 11.6(1) es8
Version 11.6(1) es9
Version 11.6(1)_fips
Version 12.0(1)
Version 12.0(1) es1
Version 12.0(1) es2
Version 12.0(1) es3
Version 12.0(1) es4
Version 12.0(1) es5
Version 12.0(1) es6
Version 12.0(1) es7
Version 12.0(1) es8
Version 12.5(1)
Version 12.5(1) es1
Version 12.5(1) es2
Version 12.5(1) es3
Version 12.5(1) es4
Version 12.5(1) es5
Version 12.5(1) es6
Version 12.5(1) es7
Version 12.5(1) es8
Version 12.5(1) su
Version 12.5(1) su_es1
Version 12.5(1) su_es2
Version 12.5(1) su_es3
Version 12.5(2)
Version 12.6(1)
Version 12.6(1) es01
Version 12.6(1) es02
Version 12.6(1) es03
Version 12.6(1) es04
Version 12.6(1) es05
Version 12.6(1) es06
Version 12.6(1) es07
Version 12.6(1) es07_et
Version 12.6(1) es08
Version 12.6(1) es09
Version 12.6(1) es10
Version 12.6(1) es11
Version 12.6(2)
Version 12.6(2) es01
Version 12.6(2) es02
Version 12.6(2) es03
Version 12.6(2) es04
Version 12.6(2) es05
Configuration B
17 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.5(1)
Version 10.6(1)
Version 10.6(2)
Version 11.0(1)
Version 11.5(1)
Version 11.5(1)su1
Version 11.6(1)
Version 11.6(2)
Version 12.0(1)
Version 12.0(1)es02
Version 12.0(1)es03
Version 12.0(1)es04
Version 12.5(1)
Version 12.5(1)es01
Version 12.5(1)su1
Version 12.5(1)su2
Version 12.5(1)su3
Configuration C
12 vulnerable
Configuration D
10 vulnerable
Configuration E
60 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 10.0(1)su1
Version 10.0(1)su1es04
Version 10.5(1)
Version 10.5(1)su1
Version 10.5(1)su1es10
Version 10.6(1)
Version 10.6(1)su1
Version 10.6(1)su2
Version 10.6(1)su2es04
Version 10.6(1)su3
Version 10.6(1)su3es01
Version 10.6(1)su3es02
Version 10.6(1)su3es03
Version 11.0(1)su1
Version 11.0(1)su1es02
Version 11.0(1)su1es03
Version 11.5(1)es01
Version 11.5(1)su1
Version 11.5(1)su1es01
Version 11.5(1)su1es02
Version 11.5(1)su1es03
Version 11.6(1)
Version 11.6(1)es01
Version 11.6(1)es02
Version 11.6(2)
Version 11.6(2)es01
Version 11.6(2)es02
Version 11.6(2)es03
Version 11.6(2)es04
Version 11.6(2)es05
Version 11.6(2)es06
Version 11.6(2)es07
Version 11.6(2)es08
Version 12.0(1)
Version 12.0(1)es01
Version 12.0(1)es02
Version 12.0(1)es03
Version 12.0(1)es04
Version 12.5(1)
Version 12.5(1)_su01_es01
Version 12.5(1)_su01_es02
Version 12.5(1)_su01_es03
Version 12.5(1)_su02_es01
Version 12.5(1)_su02_es02
Version 12.5(1)_su02_es03
Version 12.5(1)_su02_es04
Version 12.5(1)_su03_es01
Version 12.5(1)_su03_es02
Version 12.5(1)_su03_es03
Version 12.5(1)_su03_es04
Version 12.5(1)_su03_es05
Version 12.5(1)_su03_es06
Version 12.5(1)es01
Version 12.5(1)es02
Version 12.5(1)es03
Version 12.5(1)su1
Version 12.5(1)su2
Version 12.5(1)su3
Version 8.5(1)
Version 9.0(2)su3es04
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 12.6\(2\)es_04
Configuration G
11 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Version 12.5(1)
Version 12.5(1)su1
Version 12.5(1)su2
Version 12.5(1)su3
Version 12.5(1)su4
Version 12.5(1)su5
Version 12.5(1)su6
Version 12.5(1)su7
Version 12.5(1)su8
Version 12.5(1)su8a
Version 12.5(1)su9
Configuration H
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 12.6\(2\)es06

Timeline

No history available yet.