CVE-2025-20113 is a high-severity privilege escalation vulnerability in Cisco Unified Intelligence Center and Unified Contact Center Express. It allows an authenticated, remote attacker to elevate privileges to Administrator for specific functions due to insufficient server-side validation of user-supplied parameters. A successful exploit could lead to unauthorized access, modification, or deletion of data, potentially exposing sensitive information. While the CVSS score is 7.1 (High), there is currently no public exploit code, and it is not known to be actively exploited. Community discussion and media coverage are minimal, suggesting low current attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_intelligence_center:10.5\(1\):*:*:*:*:*:*:* | ||
11.0\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_intelligence_center:11.0\(1\):*:*:*:*:*:*:* | ||
11.0\(2\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_intelligence_center:11.0\(2\):*:*:*:*:*:*:* | ||
11.0\(3\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_intelligence_center:11.0\(3\):*:*:*:*:*:*:* | ||
11.5\(1\)CPE matchmatch criteria | cpe:2.3:a:cisco:unified_intelligence_center:11.5\(1\):*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.