CVE-2025-20278

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user.

This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
ciscoCNA
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
ciscofinesse
10.5\(1\)
ciscofinesse
10.5\(1\)_es1
ciscofinesse
10.5\(1\)_es2
ciscofinesse
10.5\(1\)_es3
ciscofinesse
10.5\(1\)_es4
ciscofinesse
10.5\(1\)_es5
ciscofinesse
10.5\(1\)_es6
ciscofinesse
10.5\(1\)_es7
ciscofinesse
10.5\(1\)_es8
ciscofinesse
10.5\(1\)_es9
ciscofinesse
10.5\(1\)_es10
ciscofinesse
11.0\(1\)
ciscofinesse
11.0\(1\):es1
ciscofinesse
11.0\(1\):es2
ciscofinesse
11.0\(1\):es3
ciscofinesse
11.0\(1\):es4
ciscofinesse
11.0\(1\):es5
ciscofinesse
11.0\(1\):es6
ciscofinesse
11.0\(1\):es7
ciscofinesse
11.5\(1\)
ciscofinesse
11.5\(1\):es1
ciscofinesse
11.5\(1\):es2
ciscofinesse
11.5\(1\):es3
ciscofinesse
11.5\(1\):es4
ciscofinesse
11.5\(1\):es5
ciscofinesse
11.5\(1\):es6
ciscofinesse
11.6\(1\)
ciscofinesse
11.6\(1\):es1
ciscofinesse
11.6\(1\):es10
ciscofinesse
11.6\(1\):es11
ciscofinesse
11.6\(1\):es2
ciscofinesse
11.6\(1\):es3
ciscofinesse
11.6\(1\):es4
ciscofinesse
11.6\(1\):es5
ciscofinesse
11.6\(1\):es6
ciscofinesse
11.6\(1\):es7
ciscofinesse
11.6\(1\):es8
ciscofinesse
11.6\(1\):es9
ciscofinesse
11.6\(1\)_fips
ciscofinesse
12.0\(1\)
ciscofinesse
12.0\(1\):es1
ciscofinesse
12.0\(1\):es2
ciscofinesse
12.0\(1\):es3
ciscofinesse
12.0\(1\):es4
ciscofinesse
12.0\(1\):es5
ciscofinesse
12.0\(1\):es6
ciscofinesse
12.0\(1\):es7
ciscofinesse
12.0\(1\):es8
ciscofinesse
12.5\(1\)
ciscofinesse
12.5\(1\):es1
ciscofinesse
12.5\(1\):es2
ciscofinesse
12.5\(1\):es3
ciscofinesse
12.5\(1\):es4
ciscofinesse
12.5\(1\):es5
ciscofinesse
12.5\(1\):es6
ciscofinesse
12.5\(1\):es7
ciscofinesse
12.5\(1\):es8
ciscofinesse
12.5\(1\):su
ciscofinesse
12.5\(1\):su_es1
ciscofinesse
12.5\(1\):su_es2
ciscofinesse
12.5\(1\):su_es3
ciscofinesse
12.5\(2\)
ciscofinesse
12.6\(1\)
ciscofinesse
12.6\(1\):es01
ciscofinesse
12.6\(1\):es02
ciscofinesse
12.6\(1\):es03
ciscofinesse
12.6\(1\):es04
ciscofinesse
12.6\(1\):es05
ciscofinesse
12.6\(1\):es06
ciscofinesse
12.6\(1\):es07
ciscofinesse
12.6\(1\):es07_et
ciscofinesse
12.6\(1\):es08
ciscofinesse
12.6\(1\):es09
ciscofinesse
12.6\(1\):es10
ciscofinesse
12.6\(1\):es11
ciscofinesse
12.6\(2\)
ciscofinesse
12.6\(2\):es01
ciscofinesse
12.6\(2\):es02
ciscofinesse
12.6\(2\):es03
ciscofinesse
12.6\(2\):es04
ciscofinesse
12.6\(2\):es05
ciscosocialminer
10.5\(1\)
ciscosocialminer
10.6\(1\)
ciscosocialminer
10.6\(2\)
ciscosocialminer
11.0\(1\)
ciscosocialminer
11.5\(1\)
ciscosocialminer
11.5\(1\)su1
ciscosocialminer
11.6\(1\)
ciscosocialminer
11.6\(2\)
ciscosocialminer
12.0\(1\)
ciscosocialminer
12.0\(1\)es02
ciscosocialminer
12.0\(1\)es03
ciscosocialminer
12.0\(1\)es04
ciscosocialminer
12.5\(1\)
ciscosocialminer
12.5\(1\)es01
ciscosocialminer
12.5\(1\)su1
ciscosocialminer
12.5\(1\)su2
ciscosocialminer
12.5\(1\)su3
ciscounified_communications_manager
12.5\(1\)
ciscounified_communications_manager
12.5\(1\)su1
ciscounified_communications_manager
12.5\(1\)su2
ciscounified_communications_manager
12.5\(1\)su3
ciscounified_communications_manager
12.5\(1\)su4
ciscounified_communications_manager
12.5\(1\)su5
ciscounified_communications_manager
12.5\(1\)su6
ciscounified_communications_manager
12.5\(1\)su7
ciscounified_communications_manager
12.5\(1\)su7a
ciscounified_communications_manager
12.5\(1\)su8
ciscounified_communications_manager
12.5\(1\)su8a
ciscounified_communications_manager
12.5\(1\)su9
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su1
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su2
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su3
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su4
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su5
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su6
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su7
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su8
ciscounified_communications_manager_im_and_presence_service
12.5\(1\)su9
ciscounified_contact_center_express
8.5\(1\)
ciscounified_contact_center_express
9.0\(2\)su3es04
ciscounified_contact_center_express
10.0\(1\)su1
ciscounified_contact_center_express
10.0\(1\)su1es04
ciscounified_contact_center_express
10.5\(1\)
ciscounified_contact_center_express
10.5\(1\)su1
ciscounified_contact_center_express
10.5\(1\)su1es10
ciscounified_contact_center_express
10.6\(1\)
ciscounified_contact_center_express
10.6\(1\)su1
ciscounified_contact_center_express
10.6\(1\)su2
ciscounified_contact_center_express
10.6\(1\)su2es04
ciscounified_contact_center_express
10.6\(1\)su3
ciscounified_contact_center_express
10.6\(1\)su3es01
ciscounified_contact_center_express
10.6\(1\)su3es02
ciscounified_contact_center_express
10.6\(1\)su3es03
ciscounified_contact_center_express
11.0\(1\)su1
ciscounified_contact_center_express
11.0\(1\)su1es02
ciscounified_contact_center_express
11.0\(1\)su1es03
ciscounified_contact_center_express
11.5\(1\)es01
ciscounified_contact_center_express
11.5\(1\)su1
ciscounified_contact_center_express
11.5\(1\)su1es01
ciscounified_contact_center_express
11.5\(1\)su1es02
ciscounified_contact_center_express
11.5\(1\)su1es03
ciscounified_contact_center_express
11.6\(1\)
ciscounified_contact_center_express
11.6\(1\)es01
ciscounified_contact_center_express
11.6\(1\)es02
ciscounified_contact_center_express
11.6\(2\)
ciscounified_contact_center_express
11.6\(2\)es01
ciscounified_contact_center_express
11.6\(2\)es02
ciscounified_contact_center_express
11.6\(2\)es03
ciscounified_contact_center_express
11.6\(2\)es04
ciscounified_contact_center_express
11.6\(2\)es05
ciscounified_contact_center_express
11.6\(2\)es06
ciscounified_contact_center_express
11.6\(2\)es07
ciscounified_contact_center_express
11.6\(2\)es08
ciscounified_contact_center_express
12.0\(1\)
ciscounified_contact_center_express
12.0\(1\)es01
ciscounified_contact_center_express
12.0\(1\)es02
ciscounified_contact_center_express
12.0\(1\)es03
ciscounified_contact_center_express
12.0\(1\)es04
ciscounified_contact_center_express
12.5\(1\)
ciscounified_contact_center_express
12.5\(1\)_su01_es01
ciscounified_contact_center_express
12.5\(1\)_su01_es02
ciscounified_contact_center_express
12.5\(1\)_su01_es03
ciscounified_contact_center_express
12.5\(1\)_su02_es01
ciscounified_contact_center_express
12.5\(1\)_su02_es02
ciscounified_contact_center_express
12.5\(1\)_su02_es03
ciscounified_contact_center_express
12.5\(1\)_su02_es04
ciscounified_contact_center_express
12.5\(1\)_su03_es01
ciscounified_contact_center_express
12.5\(1\)_su03_es02
ciscounified_contact_center_express
12.5\(1\)_su03_es03
ciscounified_contact_center_express
12.5\(1\)_su03_es04
ciscounified_contact_center_express
12.5\(1\)_su03_es05
ciscounified_contact_center_express
12.5\(1\)_su03_es06
ciscounified_contact_center_express
12.5\(1\)es01
ciscounified_contact_center_express
12.5\(1\)es02
ciscounified_contact_center_express
12.5\(1\)es03
ciscounified_contact_center_express
12.5\(1\)su1
ciscounified_contact_center_express
12.5\(1\)su2
ciscounified_contact_center_express
12.5\(1\)su3
ciscounified_intelligence_center
𝑥
< 12.6\(2\)es_04
ciscounity_connection
12.5\(1\)
ciscounity_connection
12.5\(1\)su1
ciscounity_connection
12.5\(1\)su2
ciscounity_connection
12.5\(1\)su3
ciscounity_connection
12.5\(1\)su4
ciscounity_connection
12.5\(1\)su5
ciscounity_connection
12.5\(1\)su6
ciscounity_connection
12.5\(1\)su7
ciscounity_connection
12.5\(1\)su8
ciscounity_connection
12.5\(1\)su8a
ciscounity_connection
12.5\(1\)su9
ciscovirtualized_voice_browser
𝑥
< 12.6\(2\)es06
𝑥
= Vulnerable software versions