Cisco has issued a security advisory warning about two critical vulnerabilities in its Unified Contact Center Express platform that could allow remote attackers to execute arbitrary code and gain root access. The flaws, CVE-2025-20354 and CVE-2025-20358, require urgent software updates as no workarounds are available, emphasizing the importance of timely patching. #UnifiedCCX #CVE202520354 #CVE202520358
Keypoints
- Two critical vulnerabilities affect all versions of Cisco Unified Contact Center Express.
- CVE-2025-20354 allows remote code execution with root privileges via Java RMI.
- CVE-2025-20358 is an authentication bypass flaw within the CCX Editor component.
- No known workarounds exist; software updates are necessary for remediation.
- Security experts warn that exploitation attempts may occur soon, as no malicious activity has been reported yet.
Read More: https://thecyberexpress.com/cisco-warns-of-cve-2025-20354/