CVE-2025-20112
published 2025-05-21CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate…
PriorityP427medium5.1CVSS 3.1
AVLACLPRHUINSUCLIHAN
EPSS
0.12%
2.5th percentile
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.
Affected
381 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_emergency_responder | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
| cisco | cisco_finesse | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
vendor_cisco5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq83-m7pg-gg42: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate
ghsa_unreviewed·2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 GHSA-xq83-m7pg-gg42: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.
Cisco
Cisco Unified Communications Products Privilege Escalation Vulnerability
vendor_cisco·2025-05-21·CVSS 5.1
CVE-2025-20112 [MEDIUM] CWE-268 Cisco Unified Communications Products Privilege Escalation Vulnerability
Cisco Unified Communications Products Privilege Escalation Vulnerability
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device.
This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.
Cisco has released software updates that address thi
Cisco
Cisco Unified Communications Products Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20112 Cisco Unified Communications Products Privilege Escalation Vulnerability
CVE-2025-20112: Cisco Unified Communications Products Privilege Escalation Vulnerability
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor. Cisco has released software updates tha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-21
Published