Directory Traversal Vulnerability in Cisco Unified CCX Web UI
CVE-2025-20374

4.9MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 November 2025

Badges

👾 Exploit Exists

What is CVE-2025-20374?

A vulnerability exists in the web UI of Cisco Unified CCX, allowing an authenticated remote attacker to perform a directory traversal attack. This results from inadequate input validation in specific UI features. By sending a specially crafted request to the web interface, an attacker could read arbitrary files on the operating system, potentially exposing sensitive information. Successful exploitation requires valid administrative credentials, highlighting the importance of safeguarding access to administrative accounts.

Affected Version(s)

Cisco Unified Contact Center Express 10.5(1)SU1

Cisco Unified Contact Center Express 10.6(1)

Cisco Unified Contact Center Express 11.6(1)

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20374 : Directory Traversal Vulnerability in Cisco Unified CCX Web UI