Directory Traversal Vulnerability in Cisco Unified CCX Web UI
CVE-2025-20374
What is CVE-2025-20374?
A vulnerability exists in the web UI of Cisco Unified CCX, allowing an authenticated remote attacker to perform a directory traversal attack. This results from inadequate input validation in specific UI features. By sending a specially crafted request to the web interface, an attacker could read arbitrary files on the operating system, potentially exposing sensitive information. Successful exploitation requires valid administrative credentials, highlighting the importance of safeguarding access to administrative accounts.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Cisco Unified Contact Center Express 10.5(1)SU1
Cisco Unified Contact Center Express 10.6(1)
Cisco Unified Contact Center Express 11.6(1)
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved