API Vulnerability in Cisco Unified Intelligence Center Leading to Horizontal Privilege Escalation
CVE-2025-20114

4.3MEDIUM

Key Information:

Badges

👾 Exploit Exists

What is CVE-2025-20114?

A vulnerability in the Cisco Unified Intelligence Center's API allows an authenticated remote attacker to escalate privileges horizontally. This security issue arises from inadequate validation of parameters submitted in API requests. By manipulating these requests, an attacker can perform an insecure direct object reference attack, potentially gaining access to sensitive data associated with other users on the system. This exploit emphasizes the importance of secure programming practices and robust input validation procedures to mitigate unauthorized access risks.

Affected Version(s)

Cisco Unified Contact Center Express 10.6(1)

Cisco Unified Contact Center Express 10.5(1)SU1

Cisco Unified Contact Center Express 10.6(1)SU3

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20114 : API Vulnerability in Cisco Unified Intelligence Center Leading to Horizontal Privilege Escalation