Remote Code Execution Vulnerability in Cisco Unified Contact Center Express
CVE-2025-20275
5.3MEDIUM
What is CVE-2025-20275?
A flaw within Cisco Unified Contact Center Express (Unified CCX) Editor enables the insecure deserialization of Java objects, potentially allowing an unauthenticated attacker to execute arbitrary code on the affected device. This vulnerability can be exploited when an authenticated local user is tricked into opening a maliciously crafted .aef file. Should the exploit be successful, the attacker would gain the ability to execute arbitrary code on the host system, operating under the privileges of the user who initiated the action.
Affected Version(s)
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)SU3