CVE-2025-20288: Cisco Unified Contact Center Express

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.

Affected products

  • Cisco Unified Contact Center Express: version 10.5(1) only; version 10.5(1)su1 only; version 10.5(1)su1es10 only; version 10.6(1) only; version 10.6(1)su1 only; version 10.6(1)su2 only; …
  • Cisco Unified Intelligence Center: version 10.5(1) only; version 11.0(1) only; version 11.0(2) only; version 11.0(3) only; version 11.5(1) only; version 11.6(1) only; …

Published 2025-07-16. Last modified 2026-06-17.