Remote Code Execution Vulnerability in Cisco Unified CCX Management Interface
CVE-2025-20276

3.8LOW

Key Information:

Vendor

Cisco

Vendor
CVE Published:
4 June 2025

Badges

👾 Exploit Exists

What is CVE-2025-20276?

A vulnerability exists in the web-based management interface of Cisco Unified CCX, allowing an authenticated remote attacker to send a specially crafted Java object that exploits insecure deserialization. This could lead to arbitrary code execution on the device’s operating system with potential for privilege escalation. To exploit this vulnerability, the attacker must possess valid administrative credentials, which highlights the importance of robust credential management practices.

Affected Version(s)

Cisco Unified Contact Center Express 10.6(1)

Cisco Unified Contact Center Express 10.5(1)SU1

Cisco Unified Contact Center Express 10.6(1)SU3

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20276 : Remote Code Execution Vulnerability in Cisco Unified CCX Management Interface