Directory Traversal Vulnerability in Cisco Unified CCX Web UI
CVE-2025-20374
4.9MEDIUM
What is CVE-2025-20374?
A vulnerability exists in the web UI of Cisco Unified CCX, allowing an authenticated remote attacker to perform a directory traversal attack. This results from inadequate input validation in specific UI features. By sending a specially crafted request to the web interface, an attacker could read arbitrary files on the operating system, potentially exposing sensitive information. Successful exploitation requires valid administrative credentials, highlighting the importance of safeguarding access to administrative accounts.
Affected Version(s)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 11.6(1)