Authorization bypass through user-controlled key in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20114
Published: May 22, 2025
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied parameters in API requests. A remote user can perform insecure direct object reference attack and gain access to specific data that is associated with different users on the affected system.
Affected software
Cisco Unified Intelligence Center