📦 Unified Contact Center Express

by Cisco

🔍 What is Unified Contact Center Express?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20358

CRITICAL CVSS 9.4 Nov 5, 2025

This vulnerability allows unauthenticated remote attackers to bypass authentication in Cisco Unified CCX's Contact Center Express Editor, gaining administrative privileges to create and execute arbitr...

CVE-2025-20354

CRITICAL CVSS 9.8 Nov 5, 2025

This critical vulnerability in Cisco Unified CCX allows unauthenticated remote attackers to upload arbitrary files and execute commands with root privileges via the Java RMI process. It affects Cisco ...

CVE-2024-20253

CRITICAL CVSS 9.9 Jan 26, 2024

This critical vulnerability in Cisco Unified Communications and Contact Center Solutions allows unauthenticated remote attackers to execute arbitrary code on affected devices by sending crafted messag...

CVE-2022-20658

CRITICAL CVSS 9.6 Jan 14, 2022

This vulnerability allows authenticated Advanced Users to elevate their privileges to Administrator by exploiting insufficient server-side permission validation in Cisco Unified CCMP and Unified CCDM ...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2025-20113

HIGH CVSS 7.1 May 21, 2025

This vulnerability allows authenticated remote attackers to elevate privileges to Administrator level for limited functions in Cisco Unified Intelligence Center. Attackers can exploit insufficient ser...

CVE-2025-20374

MEDIUM CVSS 4.9 Nov 5, 2025

This vulnerability allows authenticated administrators in Cisco Unified CCX web UI to perform directory traversal attacks, potentially accessing arbitrary files on the underlying operating system. Onl...

CVE-2025-20375

MEDIUM CVSS 6.5 Nov 5, 2025

This vulnerability allows authenticated administrators on Cisco Unified CCX systems to upload and execute arbitrary files through the web UI, potentially gaining full system access. It affects Cisco U...

CVE-2025-20376

MEDIUM CVSS 6.5 Nov 5, 2025

This vulnerability allows authenticated administrators in Cisco Unified CCX to upload and execute arbitrary files via the web UI, leading to remote code execution with root privileges. It affects orga...

CVE-2025-20275

MEDIUM CVSS 5.3 Jun 4, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary code on Cisco Unified CCX Editor systems by exploiting insecure Java deserialization. Attackers can achieve this by tricking au...

CVE-2025-20278

MEDIUM CVSS 6.0 Jun 4, 2025

This vulnerability allows authenticated local attackers with administrative credentials to execute arbitrary commands as root on affected Cisco Unified Communications products. The issue stems from im...

CVE-2025-20129

MEDIUM CVSS 4.3 Jun 4, 2025

An unauthenticated remote attacker can exploit improper HTTP request sanitization in Cisco Customer Collaboration Platform's web chat interface to redirect chat traffic to a malicious server. This all...