CVE-2025-20358
published 2025-11-05CVE-2025-20358: A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass…
PriorityP276critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.93%
56.7th percentile
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution.
This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.
Affected
60 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
| cisco | cisco_unified_contact_center_express | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability abuses the Java Remote Method Invocation (RMI) process of Cisco Unified CCX; monitor for unexpected or unauthenticated RMI connections to Unified CCX servers. ↗
- →The attack involves redirecting the CCX Editor authentication flow to a malicious server; monitor for CCX Editor authentication traffic directed to unexpected/external hosts. ↗
- →A successful exploit results in arbitrary script creation and execution on the Unified CCX server OS as an internal non-root user; monitor for unexpected script creation or execution events on Unified CCX servers under non-root internal accounts. ↗
- ·No workarounds are available; remediation requires applying Cisco software updates. ↗
- ·The vulnerability is rooted in improper authentication mechanisms in the CCX Editor-to-server communication channel (CWE-306), not a misconfiguration that can be tuned away. ↗
- ·This CVE is part of a broader advisory covering multiple vulnerabilities (including arbitrary file upload, CWE-434) tracked under Cisco Bug IDs CSCwq36528 and CSCwq36573; ensure all related CVEs in the advisory are addressed together. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Cisco
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
vendor_cisco·2025-11-05·CVSS 9.8
CVE-2025-20354 [CRITICAL] CWE-306 Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cc-unauth-rce-QeN8h7mQ
Cisco
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2025-20358 Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
CVE-2025-20358: Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root . For more information about these vulnerabilities, see the
CVSS: 3.1
CWE: CWE-306, CWE-434, CWE-306, CWE-434
Bug IDs: CSCwq36528, CSCwq36573, CSCwq36528, CSCwq36573
GHSA
GHSA-w3hc-3vf9-xjj9: A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass
ghsa_unreviewed·2025-11-05
CVE-2025-20358 [CRITICAL] CWE-306 GHSA-w3hc-3vf9-xjj9: A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative permissions pertaining to script creation and execution.
This vulnerability is due to improper authentication mechanisms in the communication between the CCX Editor and an affected Unified CCX server. An attacker could exploit this vulnerability by redirecting the authentication flow to a malicious server and tricking the CCX Editor into believing the authentication was successful. A successful exploit could allow the attacker to create and execute arbitrary scripts on the underlying operating system of an affected Unified CCX server, as an internal non-root user account.
No detection rules found.
No public exploits indexed.
2025-11-05
Published