CVE-2025-20374
Cisco Unified Contact Center Express Arbitrary File Download Vulnerability
Description
A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A successful exploit could allow the attacker to gain read access to arbitrary files on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.
Weakness: CWE-22
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Cisco | Cisco Contact Center | Other Products | cna-assigner |
Vendor-reported products (1)
- Cisco · Cisco Unified Contact Center Express
Vendor advisory
cisco-sa-cc-mult-vuln-gK4TFXSn
Multiple Cisco Contact Center Products Vulnerabilities
Cisco’s rating: Medium (advisory CVSS 6.5) · Published Nov 5, 2025 · updated Nov 18, 2025 (revision 1.2)
Bug IDs: CSCwq36567 , CSCwq36596 , CSCwq36645 , CSCwq36646 , CSCwq53352
The vendor’s rating applies to the whole advisory and can differ from this CVE’s own CVSS severity. Where this comes from