Client-Side Enforcement of Server-Side Security in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20113
Published: May 22, 2025
Vulnerability identifier: #VU109644
CSH Severity: Medium
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20113
CWE-ID: CWE-602
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. A remote user can access, modify, or delete data beyond the sphere of their intended access level.
Affected software
Cisco Unified Contact Center Express
Cisco Unified Intelligence Center
Cisco Unified Intelligence Center
How to mitigate CVE-2025-20113
Install updates from vendor's website.
Cisco Unified Intelligence Center - addressed in versions 12.5(1)SU ES04, 12.6(2)ES04