CVE-2025-20288: Cisco Unified Contact Center Express
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.
Affected products
- Cisco Unified Contact Center Express: version 10.5(1) only; version 10.5(1)su1 only; version 10.5(1)su1es10 only; version 10.6(1) only; version 10.6(1)su1 only; version 10.6(1)su2 only; …
- Cisco Unified Intelligence Center: version 10.5(1) only; version 11.0(1) only; version 11.0(2) only; version 11.0(3) only; version 11.5(1) only; version 11.6(1) only; …
Published 2025-07-16. Last modified 2026-06-17.