Warning: Hardcoded credentials in Cisco Unified Communications Manager, Patch Immediately!
ID: 3ecf7be5-373b-520d-b121-5b32603bf74e
STIX ID: report--3ecf7be5-373b-520d-b121-5b32603bf74e
Threat Score
A critical vulnerability (CVE-2025-20309, CVSS 10) in Cisco Unified Communications Manager and Unified CM SME allows unauthenticated attackers to obtain root via hard-coded, non-removable SSH credentials; organizations are urged to apply patches immediately, review logs for root SSH access, and strengthen monitoring and detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
