Remote Code Execution Vulnerability in Cisco Unified Contact Center Express
CVE-2025-20275
7.8HIGH
What is CVE-2025-20275?
A flaw within Cisco Unified Contact Center Express (Unified CCX) Editor enables the insecure deserialization of Java objects, potentially allowing an unauthenticated attacker to execute arbitrary code on the affected device. This vulnerability can be exploited when an authenticated local user is tricked into opening a maliciously crafted .aef file. Should the exploit be successful, the attacker would gain the ability to execute arbitrary code on the host system, operating under the privileges of the user who initiated the action.
Affected Version(s)
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)SU3
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved