CVE-2025-20114: Cisco Unified Contact Center Express
Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted API requests to an affected system to execute an insecure direct object reference attack. A successful exploit could allow the attacker to access specific data that is associated with different users on the affected system.
Affected products
- Cisco Unified Contact Center Express: version 8.5(1) only; version 9.0(2)su3es04 only; version 10.0(1)su1 only; version 10.0(1)su1es04 only; version 10.5(1) only; version 10.5(1)su1 only; …
- Cisco Unified Intelligence Center: version 10.5(1) only; version 11.0(1) only; version 11.0(2) only; version 11.0(3) only; version 11.5(1) only; version 11.6(1) only; …
Published 2025-05-21. Last modified 2026-06-17.