CVE-2025-20375 Details
Description
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute arbitrary files. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by uploading a crafted file to the web UI. A successful exploit could allow the attacker to upload arbitrary files to a vulnerable system and execute them, gaining access to the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.
A vulnerability exists in the web user interface of Cisco Unified Contact Center Express (CCX) versions 12.5 SU3 and earlier and 15.0, as well as Cisco Unified Contact Center Enterprise (CCE), Cisco Packaged Contact Center Enterprise (Packaged CCE), and Cisco Unified Intelligence Center (CUIC) versions 12.6 and earlier and 15.0. This vulnerability allows an authenticated, remote attacker to upload and execute arbitrary files on the underlying operating system. The issue arises from insufficient input validation related to specific UI features, enabling an attacker with valid administrative credentials to exploit the vulnerability by uploading a crafted file.
Cisco has released software updates to address this vulnerability. For Cisco Unified CCX, users should upgrade to version 12.5 SU3 ES07 or 15.0 ES01. For Cisco Unified Intelligence Center, version 15.0(01) ES202508 is recommended. Instructions for obtaining these updates can be found on the Cisco Support and Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-mult-vuln-gK4TFXSn | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| cisco unified contact center express | < 12.5\(1\)_su03_es07 15.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Nov 5, 2025 | New CVE Received | [email protected] |