CVE-2025-20112

MEDIUM

Cisco Unified Communications - Privilege Escalation

Title source: llm
STIX 2.1

Description

A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.

Scores

CVSS v3 5.1
EPSS 0.0007
EPSS Percentile 21.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-268
Status published
Products (50)
Cisco/Cisco Emergency Responder 12.5(1)
Cisco/Cisco Emergency Responder 12.5(1)SU1
Cisco/Cisco Emergency Responder 12.5(1)SU2
Cisco/Cisco Emergency Responder 12.5(1)SU3
Cisco/Cisco Emergency Responder 12.5(1)SU4
Cisco/Cisco Emergency Responder 12.5(1)SU5
Cisco/Cisco Emergency Responder 12.5(1)SU6
Cisco/Cisco Emergency Responder 12.5(1)SU7
Cisco/Cisco Emergency Responder 12.5(1)SU8
Cisco/Cisco Emergency Responder 12.5(1)SU8a
... and 40 more
Published May 21, 2025
Tracked Since Feb 18, 2026