Client-Side Enforcement of Server-Side Security in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20113

 

Client-Side Enforcement of Server-Side Security in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20113

Published: May 22, 2025


Vulnerability identifier: #VU109644
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20113
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. A remote user can access, modify, or delete data beyond the sphere of their intended access level.


Affected software

Cisco Unified Contact Center Express
Cisco Unified Intelligence Center

How to mitigate CVE-2025-20113

Install updates from vendor's website.

Cisco Unified Intelligence Center - addressed in versions 12.5(1)SU ES04, 12.6(2)ES04

External References

Related Security Bulletins