CVE-2025-20309
published 2025-07-02CVE-2025-20309: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could…
PriorityP277critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
1.06%
60.8th percentile
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | cisco_unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager | — | — |
| cisco | unified_communications_manager_static_ssh_credentials | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for unexpected SSH logins from the root account on Cisco Unified CM / Unified CM SME devices running Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1; these logins indicate exploitation of the static hardcoded SSH credential backdoor. ↗
- →Retrieve and review the secure syslog on affected Cisco Unified CM devices using the Cisco-provided IoC command to identify unauthorized root SSH login activity. ↗
- →Any successful unauthenticated remote SSH login as root on Cisco Unified CM should be treated as a compromise indicator, as the static root credentials cannot be changed or deleted on vulnerable versions. ↗
- ·The vulnerability only affects Cisco Unified CM and Unified CM SME Engineering Special (ES) releases 15.0.1.13010-1 through 15.0.1.13017-1; other release trains are not affected. ↗
- ·As of the advisory publication, Cisco PSIRT was not aware of proof-of-concept exploit code or active exploitation in the wild. ↗
CVSS provenance
nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
vulncheck9.8CRITICAL
vendor_cisco10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3q7w-9xf2-2f3g: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM S
ghsa_unreviewed·2025-07-02
CVE-2025-20309 [CRITICAL] CWE-798 GHSA-3q7w-9xf2-2f3g: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM S
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
VulnCheck
Cisco Smart Licensing Utility Static Credential Vulnerability
vulncheck·2024·CVSS 9.8
CVE-2024-20439 [CRITICAL] CWE-912 Cisco Smart Licensing Utility Static Credential Vulnerability
Cisco Smart Licensing Utility Static Credential Vulnerability
Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
Affected: Cisco Smart Licensing Utility
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://info.greynoise.io/hubfs/resources/GreyNoise-2025-Mass-Internet-Exploitation-Report.pdf; https://isc.sans.edu/diary/Exploit+Attempts+for+Cisco+Smart+Licensing+Utility+CVE202420439+and+CVE202420440/31782; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json;
Cisco
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
vendor_cisco·2025-07-02·CVSS 10.0
CVE-2025-20309 [CRITICAL] CWE-798 Cisco Unified Communications Manager Static SSH Credentials Vulnerability
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.
Cisco has released software u
Cisco
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
vendor_cisco·CVSS 3.1
CVE-2025-20309 Cisco Unified Communications Manager Static SSH Credentials Vulnerability
CVE-2025-20309: Cisco Unified Communications Manager Static SSH Credentials Vulnerability
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user. Cisco has releas
No detection rules found.
No public exploits indexed.
Hackernews
Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
blogs_hackernews·2026-06-04·CVSS 8.6
CVE-2026-20230 [HIGH] Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches CVE-2026-20230 in Unified CM as Exploit Code Goes Public
Cisco has patched a bug in Unified Communications Manager that lets an unauthenticated attacker on the network write files to the box and, from there, climb to root.
It is tracked as CVE-2026-20230 , and proof-of-concept exploit code is already public. Cisco's PSIRT says it has not seen the flaw used in attacks yet. The PoC shortens that runway.
The flaw is a server-side request forgery. Unified CM and its Session Management Edition fail to validate certain HTTP requests properly, so a crafted request can push the server into writing arbitrary files onto
Bleepingcomputer
Cisco warns that Unified CM has hardcoded root SSH credentials
blogs_bleepingcomputer·2025-07-02·CVSS 10.0
[CRITICAL] Cisco warns that Unified CM has hardcoded root SSH credentials
## Cisco warns that Unified CM has hardcoded root SSH credentials
## Sergiu Gatlan
Cisco has removed a backdoor account from its Unified Communications Manager (Unified CM), which would have allowed remote attackers to log in to unpatched devices with root privileges.
Cisco Unified Communications Manager (CUCM), formerly known as Cisco CallManager, serves as the central control system for Cisco's IP telephony systems, handling call routing, device management, and telephony features.
The vulnerability (tracked as CVE-2025-20309 ) was rated as maximum severity, and it is caused by static user credentials for the root account, which were intended for use during development and testing.
According to a Cisco security advisory released on Wednesday, CVE-2025-20309 affects Cisco Unified CM a
2025-07-02
Published