Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-20354


A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.


Published

2025-11-05T17:15:37.743

Last Modified

2025-11-07T15:44:35.293

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cisco unified_contact_center_express < 12.5\(1\)_su03_es07 Yes
Application cisco unified_contact_center_express 15.0 Yes

References