cbcvebase.
CVE-2025-20358
published 2025-11-05

CVE-2025-20358: A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass…

PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.93%
57.0th percentile
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution. This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.

Affected

60 ranges· showing 25
VendorProductVersion rangeFixed in
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express
ciscocisco_unified_contact_center_express

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability abuses the Java Remote Method Invocation (RMI) process of Cisco Unified CCX; monitor for unexpected or unauthenticated RMI connections to Unified CCX servers.
  • The attack involves redirecting the CCX Editor authentication flow to a malicious server; monitor for CCX Editor authentication traffic directed to unexpected/external hosts.
  • A successful exploit results in arbitrary script creation and execution on the Unified CCX server OS as an internal non-root user; monitor for unexpected script creation or execution events on Unified CCX servers under non-root internal accounts.
  • ·No workarounds are available; remediation requires applying Cisco software updates.
  • ·The vulnerability is rooted in improper authentication mechanisms in the CCX Editor-to-server communication channel (CWE-306), not a misconfiguration that can be tuned away.
  • ·This CVE is part of a broader advisory covering multiple vulnerabilities (including arbitrary file upload, CWE-434) tracked under Cisco Bug IDs CSCwq36528 and CSCwq36573; ensure all related CVEs in the advisory are addressed together.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.