Cisco Unified Intelligence Center Privilege Escalation Vulnerabilities
TL;DR 📌
Multiple privilege escalation vulnerabilities have been identified in Cisco Unified Intelligence Center, allowing authenticated remote attackers to elevate their privileges. Cisco has released software updates to address these vulnerabilities, and there are no workarounds available.
What happened 🕵️♂️
Cisco has disclosed vulnerabilities in the Cisco Unified Intelligence Center that could allow authenticated remote attackers to perform privilege escalation attacks. These vulnerabilities arise from insufficient validation of user-supplied parameters in API or HTTP requests, potentially enabling attackers to access or modify data beyond their intended access level.
Affected products 🖥️
The following products are affected by these vulnerabilities:
- Cisco Unified Intelligence Center
- Cisco Unified Contact Center Express (includes Cisco Unified Intelligence Center as part of its software bundle)
- Packaged Contact Center Enterprise
- Unified Contact Center Enterprise
Only products listed above are confirmed to be vulnerable; Cisco Finesse is not affected.
Fixed software 🔧
Upgrade to at least the first fixed release in your train (or later):
| Product / Release Train | First Fixed Release | Notes |
|---|---|---|
| ISE / ISE-PIC 12.5 | 12.5(1)SU ES04 | |
| ISE / ISE-PIC 12.6 | 12.6(2)ES04 | |
| ISE / ISE-PIC 15 | Not vulnerable. | |
| ISE / ISE-PIC 1.0 | Initial public release. |
Workarounds 🧯
There are no workarounds available to mitigate these vulnerabilities.
Risk in context 🎯
The highest CVSS score for these vulnerabilities is 7.1, categorized as HIGH severity. This indicates a significant risk for systems running affected versions of Cisco Unified Intelligence Center, particularly in environments where sensitive data is handled.
Fast facts ⚡
- Advisory ID: cisco-sa-cuis-priv-esc-3Pk96SU4
- CVSS Score: 7.1 (HIGH)
- Vulnerabilities:
- CVE-2025-20113: Privilege Escalation Vulnerability
- CVE-2025-20114: Horizontal Privilege Escalation Vulnerability
- No workarounds available.
For leadership 🧭
Executive summary. Cisco has confirmed two privilege-escalation bugs in Unified Intelligence Center, the reporting component embedded in Unified Contact Center Express, Packaged CCE and Unified CCE. There is no workaround, so any affected deployment needs the vendor’s software update scheduled and applied without waiting for a wider maintenance cycle.
Why it matters:
- Affects Cisco Unified Intelligence Center directly and any product that bundles it – Unified Contact Center Express, Packaged Contact Center Enterprise and Unified Contact Center Enterprise – so exposure isn’t limited to one product line.
- Both flaws stem from insufficient validation of user-supplied parameters in API or HTTP requests, meaning a user with a valid but limited account could reach or alter reporting data outside their assigned role.
- CVE-2025-20114 is described as horizontal privilege escalation, letting one authenticated user see or change data belonging to peers at the same access level rather than needing an admin account first.
- Cisco has published no workaround, so mitigation is limited to installing the fixed software rather than tightening configuration in the interim.
Now / Next / Later:
- Now: Identify every deployment running Cisco Unified Intelligence Center, Unified CCX, Packaged CCE or Unified CCE, and confirm which software train each is on against the advisory.
- Next: Schedule and apply Cisco’s fixed release for each affected product in your next change window, since no workaround exists to reduce risk in the meantime.
- Later: Add Unified Intelligence Center and the contact centre products that embed it to routine patch tracking, and periodically review role-based access on the reporting platform to confirm users can only reach data for their assigned role.