Jump to the main content block

【Vulnerability Alert】Two critical security vulnerabilities (CVE-2025-20354) (CVE-2025-20358) have been identified in Cisco Unified Contact Center Express (Unified CCX).

publish date : 2025-11-14 update date : 2025-11-14

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2025111103115959 Publication Time 2025/11/11 15:27
Incident Type ANA-Vulnerability Alert Discovery Time 2025/11/11 15:27
Impact Level Low  
[Subject]
【Vulnerability Alert】Two critical security vulnerabilities (CVE-2025-20354) (CVE-2025-20358) have been identified in Cisco Unified Contact Center Express (Unified CCX).
[Content]
Forwarded from TWCERTCC-200-202511-00000003

Cisco Unified Contact Center Express (Unified CCX) is a solution designed for enterprises to build customer service centers, integrating multiple service channels such as voice, instant messaging, and email to enhance customer service efficiency. Recently, Cisco released a security advisory regarding two critical vulnerabilities (CVE-2025-20354, CVSS: 9.8 and CVE-2025-20358, CVSS: 9.4). CVE-2025-20354 is a remote code execution vulnerability that allows an unauthenticated attacker to upload arbitrary files to the affected system and execute arbitrary commands with root privileges. CVE-2025-20358 is an authentication bypass vulnerability that may allow an unauthenticated remote attacker to bypass authentication and obtain administrative privileges related to script creation and execution.

Information Sharing Level: WHITE (Information content can be publicly disclosed)

[Affected Platform]
Cisco Unified Contact Center Express versions up to and including 12.5

SU3 Cisco Unified Contact Center Express version 15.0

[Recommended Actions]
Please update to the following versions: Cisco Unified Contact Center Express version 12.5 SU3 ES07 or later, and Cisco Unified Contact Center Express version 15.0 ES01 or later.
[Reference]
1. https://www.twcert.org.tw/tw/cp-169-10496-00839-1.html
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center
Click Num: