CVE-2025-20377: Cisco Packaged Contact Center Enterprise

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive information on the affected system that should be restricted. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

Affected products

  • Cisco Cisco Packaged Contact Center Enterprise: version 12.5(1) only; version 11.0(1) only; version 12.0(1) only; version 11.0(2) only; version 11.5(1) only; version 10.5(1) only; …
  • Cisco Cisco Unified Contact Center Enterprise: version 12.6(1)ES3 only; version 12.6(1)ES1 only; version 12.6(1) only; version 12.6(1)ES2 only; version 12.6(1)SecurityPatch only; version 12.5(1)ES1 only; …
  • Cisco Cisco Unified Contact Center Express: version 10.5(1)SU1 only; version 10.6(1) only; version 11.6(1) only; version 10.6(1)SU1 only; version 10.6(1)SU3 only; version 11.6(2) only; …
  • Cisco Cisco Unified Intelligence Center: version 11.6(1) only; version 10.5(1) only; version 11.0(1) only; version 11.5(1) only; version 12.0(1) only; version 12.5(1) only; …

Published 2025-11-05. Last modified 2026-06-17.