Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
TL;DR 📌
Cisco Unified Intelligence Center (CUIC) contains an authenticated arbitrary file upload vulnerability (CVE-2025-20274). An attacker with valid Report Designer (or higher) credentials could upload files, potentially execute commands and escalate to root. Fixed software is available; there are no workarounds.
What happened 🕵️♂️
Improper validation of files uploaded via the CUIC web management interface allows an authenticated remote attacker to upload arbitrary files. A successful exploit can store malicious files and execute arbitrary OS commands; Cisco raised the Security Impact Rating because an attacker could elevate privileges to root. Exploitation requires valid credentials with at least the Report Designer role. Cisco PSIRT is not aware of any public announcements or active malicious use.
Affected products 🖥️
- Cisco Unified Intelligence Center (all configurations; used in Packaged CCE and Unified CCE)
- Cisco Unified Contact Center Express (Unified CCX) — because it includes CUIC in the software bundle
Products confirmed NOT vulnerable: Cisco Finesse.
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 12.5 | 12.5(1) SU ES05 | |
| 12.6 | 12.6(2) ES05 | |
| 15 | Not vulnerable. | |
| 12.5(1)SU3 and earlier | Migrate to a fixed release. | |
| 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds that address this vulnerability.
Risk in context 🎯
- CVE: CVE-2025-20274
- CVSS v3.1 Base Score: 6.3 (Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L) — Medium severity
- Exposure drivers: network-accessible web interface (AV:N), but exploitation requires authenticated access with at least Report Designer privileges (PR:L).
- Impact: Confidentiality/integrity/availability impacts are low per CVSS, but Cisco raised the Security Impact Rating because successful exploitation can lead to root privilege escalation, increasing the operational risk on affected systems.
- Public exploitation: PSIRT is not aware of public announcements or active malicious use.
Fast facts ⚡
- Advisory ID: cisco-sa-cuis-file-upload-UhNEtStm
- Published: 2025-07-16
- Vulnerability type: Arbitrary file upload → remote command execution / privilege escalation potential
- Authentication: Required (Report Designer or higher)
- Workarounds: None
- Fix: Software updates available (see Fixed software section)
For leadership 🧭
Executive summary. Cisco Unified Intelligence Center, deployed within Packaged CCE, Unified CCE and Unified CCX, has a file upload flaw that lets a low-privileged authenticated user run commands and potentially gain root on the server. There is no workaround, so patching should be scheduled through the normal change process rather than treated as a today-emergency, given no exploitation has been observed.
Why it matters:
- The flaw sits in the CUIC web management interface, which is bundled into Packaged CCE, Unified CCE and Unified CCX deployments, so contact centre infrastructure is directly exposed.
- Any account with the Report Designer role or above is sufficient to trigger the upload and command execution, meaning the bar for a malicious or compromised low-privilege user is low.
- Cisco raised the Security Impact Rating above the CVSS score because successful exploitation can lead to root-level compromise of the affected server, not just the reporting application.
- There are no workarounds, so exposure persists until the fixed software is installed.
Now / Next / Later:
- Now: Identify every CUIC, Packaged CCE, Unified CCE and Unified CCX instance in the estate and check the software train against the fixed-release table to confirm exposure.
- Next: Schedule an upgrade to the first fixed release for your train (12.5(1) SU ES05, 12.6(2) ES05, or migrate off 12.5(1)SU3 and earlier) during a planned maintenance window.
- Later: Review who holds Report Designer or higher privileges in CUIC and tighten role assignment, since this vulnerability shows that role can be leveraged for file upload and command execution.