Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
TL;DR 📌
Multiple critical vulnerabilities have been identified in Cisco Unified Contact Center Express (Unified CCX) that could allow unauthenticated remote attackers to execute arbitrary commands and bypass authentication. Immediate action is required to mitigate these risks.
What happened 🕵️♂️
Cisco has disclosed multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express. These vulnerabilities could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root. The vulnerabilities are not dependent on one another, meaning each can be exploited independently.
Affected products 🖥️
The vulnerabilities affect all versions of Cisco Unified CCX, regardless of device configuration. Notably, the following products are confirmed not to be vulnerable:
- Packaged Contact Center Enterprise (Packaged CCE)
- Unified Contact Center Enterprise (Unified CCE)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 15.0 | 15.0 ES01 | |
| 1.0 | Initial public release. | |
| Cisco Unified CCX | 12.5 SU3 ES07 | 12.5 SU3 and earlier |
| Cisco Unified CCX | 15.0 ES01 | 15.0 |
Workarounds 🧯
There are no workarounds available to address these vulnerabilities.
Risk in context 🎯
With a CVSS score of 9.8, these vulnerabilities are rated as Critical. The risk is significant due to the potential for unauthenticated remote access, which could lead to severe impacts on system integrity and availability.
Fast facts ⚡
- CVE-2025-20354: Remote Code Execution Vulnerability (CVSS 9.8)
- CVE-2025-20358: Editor Authentication Bypass Vulnerability (CVSS 9.4)
- No workarounds available; immediate patching is essential.
For leadership 🧭
Executive summary. Any deployment of Cisco Unified Contact Center Express is exposed to unauthenticated remote takeover via its Java RMI process, with no workaround to buy time. Given the 9.8 severity and root-level impact, patching should be treated as an emergency change rather than routine maintenance.
Why it matters:
- The flaw sits in the Java RMI process of Unified CCX, a component every version of the product ships with, so exposure isn’t limited to a specific configuration.
- An unauthenticated attacker can upload arbitrary files, bypass authentication, and execute commands with root privileges — the highest level of compromise on the contact centre platform.
- CVE-2025-20354 (RCE) and CVE-2025-20358 (authentication bypass) work independently, so closing one does not neutralise the other.
- With no workaround published, network-level mitigations are the only stopgap until the fixed releases are installed.
Now / Next / Later:
- Now: Identify every Cisco Unified CCX instance in the estate and check its version against 12.5 SU3 ES07 and 15.0 ES01 to establish exposure immediately.
- Next: Schedule an emergency upgrade to 12.5 SU3 ES07 (for 12.5 SU3 and earlier) or 15.0 ES01, since no workaround exists to defer the change.
- Later: Restrict network access to the Unified CCX RMI service to trusted management hosts only, and add the platform to routine patch-tracking so future Cisco security advisories are actioned without delay.