Multiple Cisco Unified CCX Flaws Allow Attackers to Execute Arbitrary Commands
ID: fdb15678-b6fb-546c-81d1-1e9a9c6342c3
STIX ID: report--fdb15678-b6fb-546c-81d1-1e9a9c6342c3
Feed Name: Cyber Press
Cisco disclosed two critical unauthenticated Java RMI vulnerabilities in Cisco Unified Contact Center Express (CVE-2025-20354 and CVE-2025-20358): one permits arbitrary file upload and root-level remote code execution, and the other allows authentication bypass in the CCX Editor to create and run administrative scripts. Both have very high CVSS scores (9.8 and 9.4), affect CCX 12.5 SU3 and earlier and 15.0 and earlier, have no mitigations beyond upgrading, and fixed releases (12.5 SU3 ES07 and 15.0 ES01) have been published—organizations must prioritize immediate patching to avoid full contact-center compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
