Server-Side Request Forgery Risk in Cisco Unified Intelligence Center
CVE-2025-20288
5.8MEDIUM
What is CVE-2025-20288?
A security flaw in the web-based management interface of Cisco Unified Intelligence Center permits unauthenticated remote attackers to execute server-side request forgery (SSRF) attacks. This issue arises due to inadequate validation of specific HTTP requests, allowing attackers to exploit the vulnerability by sending specially crafted requests. When successfully exploited, the attacker can issue arbitrary network requests originating from the compromised device, posing serious security risks.
Affected Version(s)
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)SU3