Remote Code Execution Vulnerability in Cisco Unified CCX Management Interface
CVE-2025-20276
7.2HIGH
What is CVE-2025-20276?
A vulnerability exists in the web-based management interface of Cisco Unified CCX, allowing an authenticated remote attacker to send a specially crafted Java object that exploits insecure deserialization. This could lead to arbitrary code execution on the device’s operating system with potential for privilege escalation. To exploit this vulnerability, the attacker must possess valid administrative credentials, which highlights the importance of robust credential management practices.
Affected Version(s)
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)SU3
References
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved