cbcvebase.
CVE-2025-20354
published 2025-11-05

CVE-2025-20354: A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
55.0th percentile
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system. This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is unauthenticated arbitrary file upload via the Java RMI process of Cisco Unified CCX; monitor for unexpected file uploads or RMI traffic to/from Unified CCX nodes
  • Successful exploitation results in arbitrary command execution with root privileges; monitor for unexpected privileged process spawning from the Unified CCX Java RMI service
  • Root cause is improper authentication (CWE-306) and unrestricted file upload (CWE-434) in specific Cisco Unified CCX features exposed via Java RMI; alert on unauthenticated RMI connections to Unified CCX
  • Track Cisco Bug IDs CSCwq36528 and CSCwq36573 for patch status and internal indicators; both bugs are associated with this RCE advisory
  • ·No workarounds are available for this vulnerability; the only remediation is applying Cisco's software updates

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.