CVE-2025-20112
MEDIUMCisco Unified Communications - Privilege Escalation
Title source: llmDescription
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing crafted commands on the underlying operating system. A successful exploit could allow the attacker to escape the restricted shell and gain root privileges on the underlying operating system of an affected device. To successfully exploit this vulnerability, an attacker would need administrative access to the ESXi hypervisor.
References (1)
Core 1
Core References
Scores
CVSS v3
5.1
EPSS
0.0007
EPSS Percentile
21.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-268
Status
published
Products (50)
Cisco/Cisco Emergency Responder
12.5(1)
Cisco/Cisco Emergency Responder
12.5(1)SU1
Cisco/Cisco Emergency Responder
12.5(1)SU2
Cisco/Cisco Emergency Responder
12.5(1)SU3
Cisco/Cisco Emergency Responder
12.5(1)SU4
Cisco/Cisco Emergency Responder
12.5(1)SU5
Cisco/Cisco Emergency Responder
12.5(1)SU6
Cisco/Cisco Emergency Responder
12.5(1)SU7
Cisco/Cisco Emergency Responder
12.5(1)SU8
Cisco/Cisco Emergency Responder
12.5(1)SU8a
... and 40 more
Published
May 21, 2025
Tracked Since
Feb 18, 2026