← Back

CVE-2025-20354

nvd nist
Published: Nov 5, 2025Modified: Nov 7, 2025

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: psirt@cisco.com (Secondary)

Description

A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.

Affected (2)

1 product
Unified Contact Center Express
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Cisco
Before 12.5\(1\)_su03_es07
Version 15.0

Timeline

No history available yet.