CVE-2025-20242: Cisco Unified Contact Center Enterprise
Critical severity, CVSS 9.1. EPSS: 5.7% chance of exploitation in the next 30 days.
A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.
Affected products
- Cisco Unified Contact Center Enterprise: version 12.6(2)es2 only
Published 2025-05-21. Last modified 2026-06-17.