Remote Code Execution Vulnerability in Cisco Unified CCX Software
CVE-2025-20354
9.8CRITICAL
What is CVE-2025-20354?
A vulnerability exists in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX, allowing unauthenticated attackers to upload arbitrary files and execute commands with root privileges. This issue arises from weak authentication mechanisms linked to certain Cisco Unified CCX features. By exploiting this flaw, an attacker could manipulate an affected system to run arbitrary commands, potentially leading to significant security breaches.
Affected Version(s)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 11.6(1)