cbcvebase.
CVE-2025-20309
published 2025-07-02

CVE-2025-20309: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could…

PriorityP277critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.06%
60.8th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.

Affected

17 ranges
VendorProductVersion rangeFixed in
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscocisco_unified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager
ciscounified_communications_manager_static_ssh_credentials

Detection & IOCsextracted from sources · hover to see the quote

commandfile get activelog syslog/secure
  • Look for unexpected SSH logins from the root account on Cisco Unified CM / Unified CM SME devices running Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1; these logins indicate exploitation of the static hardcoded SSH credential backdoor.
  • Retrieve and review the secure syslog on affected Cisco Unified CM devices using the Cisco-provided IoC command to identify unauthorized root SSH login activity.
  • Any successful unauthenticated remote SSH login as root on Cisco Unified CM should be treated as a compromise indicator, as the static root credentials cannot be changed or deleted on vulnerable versions.
  • ·The vulnerability only affects Cisco Unified CM and Unified CM SME Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1; other release trains are not affected.
  • ·As of the advisory publication, Cisco PSIRT was not aware of proof-of-concept exploit code or active exploitation in the wild.

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.