API Vulnerability in Cisco Unified Intelligence Center Leading to Horizontal Privilege Escalation
CVE-2025-20114
4.3MEDIUM
What is CVE-2025-20114?
A vulnerability in the Cisco Unified Intelligence Center's API allows an authenticated remote attacker to escalate privileges horizontally. This security issue arises from inadequate validation of parameters submitted in API requests. By manipulating these requests, an attacker can perform an insecure direct object reference attack, potentially gaining access to sensitive data associated with other users on the system. This exploit emphasizes the importance of secure programming practices and robust input validation procedures to mitigate unauthorized access risks.
Affected Version(s)
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)SU3