CVE Database
/

CVE-2025-20278

Back to search

CVE-2025-20278

Published: Jun 4, 2025

Modified: Feb 26, 2026

PUBLISHED

CVSS v3.1

6.0

MEDIUM

Description

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.

VendorProductVersions

Cisco

Cisco Finesse

affected
11.0(1)ES_Rollback
affected
10.5(1)ES4
affected
11.6(1)ES3
affected
11.0(1)ES2
affected
12.0(1)ES2

+79 more versions

Cisco

Cisco SocialMiner

affected
12.5(1)ES01
affected
10.5(1)
affected
11.6(1)
affected
10.6(1)
affected
12.0(1)ES04

+12 more versions

Cisco

Cisco Unified Communications Manager

affected
12.5(1)SU2
affected
12.5(1)SU1
affected
12.5(1)
affected
12.5(1)SU3
affected
12.5(1)SU4

+16 more versions

Cisco

Cisco Unified Communications Manager IM and Presence Service

affected
12.5(1)
affected
12.5(1)SU1
affected
12.5(1)SU2
affected
12.5(1)SU3
affected
12.5(1)SU4

+14 more versions

Cisco

Cisco Unified Contact Center Express

affected
10.6(1)
affected
10.5(1)SU1
affected
10.6(1)SU3
affected
12.0(1)
affected
10.0(1)SU1

+55 more versions

Cisco

Cisco Unified Intelligence Center

affected
11.6(1)
affected
10.5(1)
affected
11.0(1)
affected
11.5(1)
affected
12.0(1)

+17 more versions

Cisco

Cisco Unity Connection

affected
12.5(1)
affected
12.5(1)SU1
affected
12.5(1)SU2
affected
12.5(1)SU3
affected
12.5(1)SU4

+14 more versions

Cisco

Cisco Virtualized Voice Browser

affected
11.0(1)
affected
11.6(1)_ES84
affected
11.5(1)_ES54
affected
11.5(1)_ES27
affected
11.5(1)

+88 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now