File Upload Vulnerability in Cisco Unified CCX Web UI
CVE-2025-20376

6.5MEDIUM

Key Information:

Vendor

Cisco

Vendor
CVE Published:
5 November 2025

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2025-20376?

A flaw in Cisco Unified Contact Center Express (CCX) allows authenticated remote attackers to upload and execute arbitrary files via the web UI. This vulnerability arises from inadequate input validation in the file upload processes. An attacker with valid administrative access can exploit this vulnerability to upload a malicious file, potentially leading to the execution of arbitrary commands on the underlying system. Successful exploitation could provide the attacker with elevated privileges, compromising the integrity and security of the system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Cisco Unified Contact Center Express 10.5(1)SU1

Cisco Unified Contact Center Express 10.6(1)

Cisco Unified Contact Center Express 11.6(1)

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.