HomeSecurityCritical vulnerabilities in Cisco Unified Contact Center Express

Critical vulnerabilities in Cisco Unified Contact Center Express

Cisco has disclosed critical vulnerabilities in Unified Contact Center Express ( CCX) that could allow unauthenticated remote attackers to execute malicious code and gain elevated privileges on vulnerable systems .

Cisco Unified Contact Center Express

The vulnerabilities affect the Java Remote Method Invocation (RMI) process and authentication mechanisms , potentially putting entire contact center deployments at risk.

See also: Multiple vulnerabilities in Django allow SQL Injection and DoS

Cisco Unified Contact Center Express: Critical Vulnerabilities

The primary vulnerability, CVE-2025-20354, has a CVSS score of 9.8/10 and allows attackers to upload arbitrary files via the Java RMI process without authentication. Successful exploitation allows attackers to execute commands with root privileges on affected systems.

The vulnerability arises from improper authentication mechanisms in Cisco Unified CCX, leaving organizations' contact center infrastructure exposed to full compromise. Attackers could exploit this weakness for persistent access, to steal sensitive customer data, or to deploy ransomware to entire contact center networks.

See also: Cisco: Hackers exploit ASA and FTD vulnerability

Critical vulnerabilities in Cisco Unified Contact Center Express

CVE -2025-20358 is also a critical authentication bypass affecting the CCX Editor application. Rated 9.4 on the CVSS scale, this vulnerability allows attackers to redirect the authentication flow to malicious servers, tricking the CCX Editor into believing that legitimate authentication has occurred.

Once bypassed, attackers gain administrative privileges to create and execute arbitrary scripts as internal non-root users. This combination of vulnerabilities creates a complex attack chain that allows remote attackers to escalate privileges and maintain control over the contact center operations.

See also: AI Engine: Vulnerability in WordPress plugin puts 100,000 sites at risk

Critical vulnerabilities in Cisco Unified Contact Center Express

Protection

Cisco has released software updates that address both vulnerabilities, with no workarounds available. Organizations using Unified CCX version 12.5 SU3 and earlier should immediately upgrade to version 12.5 SU3 ES07 . Users on version 15.0 should install version 15.0 ES01 . The vulnerabilities affect all Unified CCX configurations regardless of deployment settings.

Other Cisco products, including Unified Contact Center Enterprise (CCE) and Packaged Contact Center Enterprise, remain unaffected.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS