CVE-2025-20374
Cisco Unified Contact Center Express Arbitrary File Download Vulnerability
Severity
Medium 4.9
CVSS 3.1
Exploited
Not listed
EPSS
0.011
63.1th percentile
Discovered by
Third party
Vendor-published field
Published
Nov 5, 2025
Assigned by cisco
Description
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to arbitrary files on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Contact Center | Other Products | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Unified Contact Center Express