Multiple Cisco Contact Center Products Vulnerabilities
TL;DR 📌
Multiple vulnerabilities have been identified in Cisco Contact Center products, allowing authenticated attackers to potentially disclose sensitive information, execute arbitrary commands, and elevate privileges. The highest CVSS score is 6.5, indicating a medium risk. Users are advised to upgrade to fixed software releases as there are no available workarounds.
What happened 🕵️♂️
Cisco has disclosed multiple vulnerabilities affecting its Contact Center products, including Cisco Unified Contact Center Express (Unified CCX), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Packaged Contact Center Enterprise (Packaged CCE), and Cisco Unified Intelligence Center (CUIC). These vulnerabilities can be exploited by authenticated remote attackers to disclose sensitive information, upload and execute arbitrary files, and elevate privileges to root. Successful exploitation requires valid user credentials.
Affected products 🖥️
The vulnerabilities affect the following products:
- Cisco Unified Contact Center Express (Unified CCX)
- Cisco Unified Contact Center Enterprise (Unified CCE)
- Cisco Packaged Contact Center Enterprise (Packaged CCE)
- Cisco Unified Intelligence Center (CUIC)
Fixed software 🔧
Upgrade to the first fixed release in your train (or later):
| Release / Product | First Fixed Release | Notes |
|---|---|---|
| 15.0 | 15.0 ES01 | |
| 12.6 and earlier | Migrate to a fixed release. | |
| 15.0 | 15.0(01) ES202508 | |
| 1.0 | Initial public release. | |
| Cisco Unified CCX | 12.5 SU3 ES07 | 12.5 SU3 and earlier |
| Cisco Unified CCX | 15.0 ES01 | 15.0 |
| Cisco Unified Intelligence Center | Migrate to a fixed release | 12.6 and earlier |
| Cisco Unified Intelligence Center | 15.0(01) ES202508 | 15.0 |
Workarounds 🧯
There are no workarounds available for these vulnerabilities.
Risk in context 🎯
The vulnerabilities present a medium risk (CVSS score of 6.5) primarily due to the requirement for valid credentials to exploit them. This means that while the attack surface is limited to authenticated users, the potential for sensitive data exposure and system compromise remains significant. Organizations using the affected Cisco products should prioritize upgrading to the fixed software releases to mitigate these risks.
Fast facts ⚡
- Highest CVSS Score: 6.5 (Medium)
- Attack Vector: Requires authenticated access
- Exploitation Impact: Sensitive information disclosure, arbitrary file upload, remote code execution, privilege escalation
- Workarounds: None available
For leadership 🧭
Executive summary. Cisco’s contact centre suite - Unified CCX, Unified CCE, Packaged CCE and Unified Intelligence Center - has several flaws that let a logged-in user escalate to root, disclose sensitive data or run arbitrary code, with no workaround available. There is no known exploitation yet, but given these systems typically hold customer call and CRM data, patching should be scheduled promptly rather than treated as routine maintenance.
Why it matters:
- Exploitation requires only valid user credentials, not administrative rights, so any authenticated agent or supervisor account is a potential launch point for privilege escalation to root.
- Affected systems - Unified CCX, Unified CCE, Packaged CCE and Unified Intelligence Center - sit at the core of contact centre operations and typically handle customer records and call routing data, making information disclosure here directly relevant to customer data protection.
- Arbitrary file upload and execution on these platforms could let an authenticated attacker plant persistent code on infrastructure that is often tightly integrated with telephony and CRM backends.
- No workaround exists, meaning the only mitigation is upgrading, so exposure continues in full until the fixed release is deployed.
Now / Next / Later:
- Now: Identify which Contact Center Express, Enterprise, Packaged CCE or Unified Intelligence Center instances you run and confirm their current release train against the fixed versions listed by Cisco.
- Next: Schedule an upgrade in your next change window to the first fixed release for your train - for example 12.5 SU3 ES07 or 15.0 ES01 for Unified CCX, or 15.0(01) ES202508 for CUIC and Unified CCE/Packaged CCE - since no workaround is available.
- Later: Review credential hygiene and access reviews for contact centre agent and supervisor accounts, and build Cisco Contact Center advisories into a routine patch cadence given the platform’s reliance on fixed-release upgrades rather than configurable mitigations.