Remote Code Execution Vulnerability in Cisco Unified Contact Center Express
CVE-2025-20275

5.3MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 June 2025

Badges

👾 Exploit Exists

What is CVE-2025-20275?

A flaw within Cisco Unified Contact Center Express (Unified CCX) Editor enables the insecure deserialization of Java objects, potentially allowing an unauthenticated attacker to execute arbitrary code on the affected device. This vulnerability can be exploited when an authenticated local user is tricked into opening a maliciously crafted .aef file. Should the exploit be successful, the attacker would gain the ability to execute arbitrary code on the host system, operating under the privileges of the user who initiated the action.

Affected Version(s)

Cisco Unified Contact Center Express 10.6(1)

Cisco Unified Contact Center Express 10.5(1)SU1

Cisco Unified Contact Center Express 10.6(1)SU3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20275 : Remote Code Execution Vulnerability in Cisco Unified Contact Center Express