CVE-2025-20374

Cisco Unified Contact Center Express Arbitrary File Download Vulnerability

Severity
Medium 4.9
CVSS 3.1
Exploited
Not listed
EPSS
0.011
63.1th percentile
Discovered by
Third party
Vendor-published field
Published
Nov 5, 2025
Assigned by cisco

Description

A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to arbitrary files on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.

Weakness: CWE-22

Affected products

Vendor Product Category Matched by
Cisco Cisco Contact Center Other Products cna-assigner
Vendor-reported products (1)
  • Cisco · Cisco Unified Contact Center Express

Something wrong here?