Known vulnerabilities in Cisco Unified Contact Center Express (Unified CCX)
Vendor:
Cisco Systems, Inc
Software CPE:
cpe:2.3:a:cisco_systems:cisco_unified_contact_center_express_unified_ccx:*:*:*:*:*:*:*:*
Website:
https://www.cisco.com
Total vulnerabilities:
5
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
Vulnerabilities (5)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU118149 - Unrestricted Upload of File with Dangerous Type CVE-2025-20376 |
CWE-434 | Low | 12.5 SU3 ES07, 15.0 ES01 | 06.11.2025 |
SB2025110615 |
||
| #VU118148 - Unrestricted Upload of File with Dangerous Type CVE-2025-20375 |
CWE-434 | Low | 12.5 SU3 ES07, 15.0 ES01 | 06.11.2025 |
SB2025110615 |
||
| #VU118147 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-20374 |
CWE-22 | Low | 12.5 SU3 ES07, 15.0 ES01 | 06.11.2025 |
SB2025110615 |
||
| #VU113011 - Unrestricted Upload of File with Dangerous Type CVE-2025-20274 |
CWE-434 | Medium | - | 17.07.2025 |
SB2025071715 |
||
| #VU113010 - Server-Side Request Forgery (SSRF) CVE-2025-20288 |
CWE-918 | Medium | - | 17.07.2025 |
SB2025071715 |