Authorization bypass through user-controlled key in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20114

 

Authorization bypass through user-controlled key in Cisco Unified Contact Center Express and Cisco Unified Intelligence Center - CVE-2025-20114

Published: May 22, 2025


Vulnerability identifier: #VU109645
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20114
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied parameters in API requests. A remote user can perform insecure direct object reference attack and gain access to specific data that is associated with different users on the affected system.


Affected software

Cisco Unified Contact Center Express
Cisco Unified Intelligence Center

How to mitigate CVE-2025-20114

Install updates from vendor's website.

Cisco Unified Intelligence Center - addressed in versions 12.5(1)SU ES04, 12.6(2)ES04

External References

Related Security Bulletins