API Vulnerability in Cisco Unified Intelligence Center
CVE-2025-20377
4.3MEDIUM
What is CVE-2025-20377?
A vulnerability exists in the API subsystem of Cisco Unified Intelligence Center, enabling an authenticated remote attacker to access sensitive information. Due to improper validation of requests to designated API endpoints, a low-privileged user could exploit this flaw by sending valid requests, potentially allowing them to view restricted data within the affected system. To successfully exploit this vulnerability, the attacker must possess valid user credentials.
Affected Version(s)
Cisco Packaged Contact Center Enterprise 12.5(1)
Cisco Packaged Contact Center Enterprise 11.0(1)
Cisco Packaged Contact Center Enterprise 12.0(1)