CVE 6.5 MEDIUM

Cisco Unified Contact Center Express Remote Code Execution Vulnerability_CVE-2025-20376

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Description

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files.

This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exploit this vulnerability by uploading a malicious file to the web UI and executing it. A successful exploit could allow the attacker to execute arbitrary commands on the underlying system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.

Basic Information

ID CVE-2025-20376
Source cisco
Published Nov 5, 2025 at 16:31
Modified Nov 5, 2025 at 20:12

Affected Product

Vendor Cisco
Product Cisco Unified Contact Center Express
Version 10.5(1)SU1
Affected Versions Cisco Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Cisco Unified Contact Center Express 10.6(1)
Cisco Cisco Unified Contact Center Express 11.6(1)
Cisco Cisco Unified Contact Center Express 10.6(1)SU1
Cisco Cisco Unified Contact Center Express 10.6(1)SU3
Cisco Cisco Unified Contact Center Express 11.6(2)
Cisco Cisco Unified Contact Center Express 12.0(1)
Cisco Cisco Unified Contact Center Express 11.0(1)SU1
Cisco Cisco Unified Contact Center Express 11.5(1)SU1
Cisco Cisco Unified Contact Center Express 10.5(1)
Cisco Cisco Unified Contact Center Express 12.5(1)
Cisco Cisco Unified Contact Center Express 12.5(1)SU1
Cisco Cisco Unified Contact Center Express 12.5(1)SU2
Cisco Cisco Unified Contact Center Express 12.5(1)SU3
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES01
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES04
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU02_ES01
Cisco Cisco Unified Contact Center Express 11.6(2)ES07
Cisco Cisco Unified Contact Center Express 11.6(2)ES08
Cisco Cisco Unified Contact Center Express 12.5(1)_SU01_ES01
Cisco Cisco Unified Contact Center Express 12.0(1)ES04
Cisco Cisco Unified Contact Center Express 12.5(1)ES02
Cisco Cisco Unified Contact Center Express 12.5(1)ES03
Cisco Cisco Unified Contact Center Express 11.6(2)ES06
Cisco Cisco Unified Contact Center Express 12.5(1)ES01
Cisco Cisco Unified Contact Center Express 12.0(1)ES03
Cisco Cisco Unified Contact Center Express 12.0(1)ES01
Cisco Cisco Unified Contact Center Express 11.6(2)ES05
Cisco Cisco Unified Contact Center Express 12.0(1)ES02
Cisco Cisco Unified Contact Center Express 11.6(2)ES04
Cisco Cisco Unified Contact Center Express 11.6(2)ES03
Cisco Cisco Unified Contact Center Express 11.6(2)ES02
Cisco Cisco Unified Contact Center Express 11.6(2)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES03
Cisco Cisco Unified Contact Center Express 11.0(1)SU1ES03
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES01
Cisco Cisco Unified Contact Center Express 10.5(1)SU1ES10
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES03
Cisco Cisco Unified Contact Center Express 11.6(1)ES02
Cisco Cisco Unified Contact Center Express 11.5(1)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU2
Cisco Cisco Unified Contact Center Express 10.6(1)SU2ES04
Cisco Cisco Unified Contact Center Express 11.6(1)ES01
Cisco Cisco Unified Contact Center Express 10.6(1)SU3ES02
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES02
Cisco Cisco Unified Contact Center Express 11.5(1)SU1ES01
Cisco Cisco Unified Contact Center Express 11.0(1)SU1ES02
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES03
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES04
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES05
Cisco Cisco Unified Contact Center Express UCCX 15.0.1
Cisco Cisco Unified Contact Center Express 12.5(1)_SU03_ES06

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.