A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exploit this vulnerability by uploading a malicious file to the web UI and executing it. A successful exploit could allow the attacker to execute arbitrary commands on the underlying system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.
History

Thu, 06 Nov 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco unified Contact Center Express
Vendors & Products Cisco
Cisco unified Contact Center Express

Wed, 05 Nov 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to file upload mechanisms. An attacker could exploit this vulnerability by uploading a malicious file to the web UI and executing it. A successful exploit could allow the attacker to execute arbitrary commands on the underlying system and elevate privileges to root. To exploit this vulnerability, the attacker must have valid administrative credentials.
Title Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published: 2025-11-05T16:31:38.793Z

Updated: 2025-11-06T04:55:44.673Z

Reserved: 2024-10-10T19:15:13.262Z

Link: CVE-2025-20376

cve-icon Vulnrichment

Updated: 2025-11-05T20:11:56.012Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-05T17:15:38.953

Modified: 2025-11-06T19:45:30.990

Link: CVE-2025-20376

cve-icon Redhat

No data.