Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20242


A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.


Published

2025-05-21T17:15:56.190

Last Modified

2025-07-11T15:20:30.753

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco unified_contact_center_enterprise 12.6\(2\)es2 Yes

References