Cisco Customer Collaboration Platform Information Disclosure Vulnerability

🚨 SEVERITY: MEDIUM β€” CVSS 4.3 Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the…
  • No fixed release listed yet; apply mitigations and monitor.
  • Workarounds are documented in the advisory.
  • CVEs: CVE-2025-20129.

What happened πŸ•΅οΈβ€β™‚οΈ

A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.

This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the chat interface of a targeted user on a vulnerable server. A successful exploit could allow the attacker to redirect chat traffic to a server that is under their control, resulting in sensitive information being redirected to the attacker.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

Affected products πŸ–₯️

At the time of publication, this vulnerability affected Cisco CCP.

For information about which Cisco software releases were vulnerable at the time of publication, see the Fixed Software ["#fs"] section of this advisory. See the Details section in the bug ID(s) at the top of this advisory for the most complete and current information.

Fixed software πŸ”§

Upgrade to the first fixed release in your train (or later):

Release / Product First Fixed Release Notes
15.0 Not vulnerable. Note: The fixed software for CCP/SocialMiner is included in the Unified Contact Center Express 15.0(1) download.
1.0 Initial public release.

Workarounds 🧯

There are no workarounds that address this vulnerability.

Risk in context 🎯

Use vendor CVSS for prioritization. Consider exposure and asset criticality.

Fast facts ⚑

  • Advisory: cisco-sa-ccp-info-disc-ZyGerQpd
  • Initial release: 2025-06-04T16:00:00 UTC
  • Last updated: 2025-06-04T16:00:00 UTC

For leadership 🧭

Executive summary. An unauthenticated remote attacker can manipulate the web chat interface of Cisco Customer Collaboration Platform so that a customer’s chat session is redirected to a server the attacker controls, exposing whatever is typed in that chat. There is no workaround, so this should be reviewed and scheduled for remediation as soon as a fixed release is confirmed for your train.

Why it matters:

  • The flaw sits in the web-based chat interface of Cisco CCP (formerly SocialMiner), which is customer-facing and reachable without authentication.
  • Crafted HTTP requests can redirect an individual user’s chat traffic to an attacker-controlled server, exposing whatever that customer types into the chat window.
  • Cisco has not published a workaround, so exposure remains until the affected release is upgraded.
  • Only CCP/SocialMiner 1.0 and earlier trains are affected; 15.0 (delivered via Unified Contact Center Express 15.0(1)) is confirmed not vulnerable.

Now / Next / Later:

  • Now: Identify every CCP/SocialMiner instance in your environment and check which release train it runs against the advisory’s fixed-software table.
  • Next: Plan an upgrade to Unified Contact Center Express 15.0(1), which includes the fixed CCP/SocialMiner software, since no workaround is available.
  • Later: Add CCP/SocialMiner version tracking to your patch inventory so future advisories against this component are matched to affected instances without a manual audit.