CVE-2025-20354
published 2025-11-05CVE-2025-20354: A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary…
PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.88%
55.0th percentile
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system.
This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is unauthenticated arbitrary file upload via the Java RMI process of Cisco Unified CCX; monitor for unexpected file uploads or RMI traffic to/from Unified CCX nodes ↗
- →Successful exploitation results in arbitrary command execution with root privileges; monitor for unexpected privileged process spawning from the Unified CCX Java RMI service ↗
- →Root cause is improper authentication (CWE-306) and unrestricted file upload (CWE-434) in specific Cisco Unified CCX features exposed via Java RMI; alert on unauthenticated RMI connections to Unified CCX ↗
- →Track Cisco Bug IDs CSCwq36528 and CSCwq36573 for patch status and internal indicators; both bugs are associated with this RCE advisory ↗
- ·No workarounds are available for this vulnerability; the only remediation is applying Cisco's software updates ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-px5r-4v6x-q5mv: A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbi
ghsa_unreviewed·2025-11-05
CVE-2025-20354 [CRITICAL] CWE-434 GHSA-px5r-4v6x-q5mv: A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbi
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arbitrary files and execute arbitrary commands with root permissions on an affected system.
This vulnerability is due to improper authentication mechanisms that are associated to specific Cisco Unified CCX features. An attacker could exploit this vulnerability by uploading a crafted file to an affected system through the Java RMI process. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system and elevate privileges to root.
Cisco
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
vendor_cisco·2025-11-05·CVSS 9.8
CVE-2025-20354 [CRITICAL] CWE-306 Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ
Cisco
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20354 Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
CVE-2025-20354: Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root . For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-306, CWE-434, CWE-306, CWE-434
Bug IDs: CSCwq36528, CSCwq36573, CSCwq36528, CSCwq36573
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Cisco: Actively exploited firewall flaws now abused for DoS attacks
blogs_bleepingcomputer·2025-11-07·CVSS 9.9
CVE-2025-20362 [CRITICAL] Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Cisco: Actively exploited firewall flaws now abused for DoS attacks
## Sergiu Gatlan
Cisco warned this week that two vulnerabilities, which have been used in zero-day attacks, are now being exploited to force ASA and FTD firewalls into reboot loops.
The tech giant released security updates on September 25 to address the two security flaws, stating that CVE-2025-20362 enables remote threat actors to access restricted URL endpoints without authentication, while CVE-2025-20333 allows authenticated attackers to gain remote code execution on vulnerable devices.
When chained, these vulnerabilities allow remote, unauthenticated attackers to gain complete control over unpatched systems.
The same day, CISA issued an emergency directive ordering U.S. federal agencies to secure their Cisco fi
Bleepingcomputer
Critical Cisco UCCX flaw lets attackers run commands as root
blogs_bleepingcomputer·2025-11-06·CVSS 9.8
CVE-2025-20354 [CRITICAL] Critical Cisco UCCX flaw lets attackers run commands as root
## Critical Cisco UCCX flaw lets attackers run commands as root
## Sergiu Gatlan
Cisco has released security updates to patch a critical vulnerability in the Unified Contact Center Express (UCCX) software, which could enable attackers to execute commands with root privileges.
The Cisco UCCX platform, described by the company as a "contact center in a box," is a software solution for managing customer interactions in call centers, supporting up to 400 agents.
Tracked as CVE-2025-20354 , this security flaw was discovered in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX by security researcher Jahmel Harris, allowing unauthenticated attackers to execute arbitrary commands remotely with root permissions.
"This vulnerability is due to improper authentication mechanism
2025-11-05
Published