CVE 9.4 CRITICAL

Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability_CVE-2025-20358

9.4 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Description

A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution.

This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.

AI Analysis

AI processing failed - no valid JSON found

Basic Information

ID CVE-2025-20358
Source cisco
Published Nov 5, 2025 at 16:31
Modified Nov 5, 2025 at 20:09

Affected Product

Vendor Cisco
Product Cisco Unified Contact Center Express
Version 10.5(1)SU1
Affected Versions Cisco Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Cisco Unified Contact Center Express 10.6(1)
Cisco Cisco Unified Contact Center Express 11.6(1)
Cisco Cisco Unified Contact Center Express 10.6(1)SU1
Cisco Cisco Unified Contact Center Express 10.6(1)SU3
Cisco Cisco Unified Contact Center Express 11.6(2)
Cisco Cisco Unified Contact Center Express 12.0(1)
Cisco Cisco Unified Contact Center Express 11.0(1)SU1
Cisco Cisco Unified Contact Center Express 11.5(1)SU1
Cisco Cisco Unified Contact Center Express 10.5(1)
Cisco Cisco Unified Contact Center Express 12.5(1)
Cisco Cisco Unified Contact Center Express 12.5(1)SU1
Cisco Cisco Unified Contact Center Express 12.5(1)SU2
Cisco Cisco Unified Contact Center Express 12.5(1)SU3
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES01
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES04
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES01
Cisco Cisco Unified Contact Center Express 11.6(2)ES07
Cisco Cisco Unified Contact Center Express 11.6(2)ES08
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES01
Cisco Cisco Unified Contact Center Express 12.0(1)ES04
Cisco Cisco Unified Contact Center Express 12.5(1)ES02
Cisco Cisco Unified Contact Center Express 12.5(1)ES03
Cisco Cisco Unified Contact Center Express 11.6(2)ES06
Cisco Cisco Unified Contact Center Express 12.5(1)ES01
Cisco Cisco Unified Contact Center Express 12.0(1)ES03
Cisco Cisco Unified Contact Center Express 12.0(1)ES01
Cisco Cisco Unified Contact Center Express 11.6(2)ES05
Cisco Cisco Unified Contact Center Express 12.0(1)ES02
Cisco Cisco Unified Contact Center Express 11.6(2)ES04
Cisco Cisco Unified Contact Center Express 11.6(2)ES03
Cisco Cisco Unified Contact Center Express 11.6(2)ES02
Cisco Cisco Unified Contact Center Express 11.6(2)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES03
Cisco Cisco Unified Contact Center Express 11.0(1)SU1ES03
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES01
Cisco Cisco Unified Contact Center Express 10.5(1)SU1ES10
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES03
Cisco Cisco Unified Contact Center Express 11.6(1)ES02
Cisco Cisco Unified Contact Center Express 11.5(1)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU2
Cisco Cisco Unified Contact Center Express 10.6(1)SU2ES04
Cisco Cisco Unified Contact Center Express 11.6(1)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES02
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES02
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES01
Cisco Cisco Unified Contact Center Express 11.0(1)SU1ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES04
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES05
Cisco Cisco Unified Contact Center Express UCCX 15.0.1
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES06

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.