CVE-2025-20377
MEDIUMCisco Unified Intelligence Center - Info Disclosure
Title source: llmDescription
A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive information on the affected system that should be restricted. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.
References (1)
Core 1
Core References
Scores
CVSS v3
4.3
EPSS
0.0005
EPSS Percentile
15.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (50)
Cisco/Cisco Packaged Contact Center Enterprise
10.5(1)
Cisco/Cisco Packaged Contact Center Enterprise
10.5(1)_ES7
Cisco/Cisco Packaged Contact Center Enterprise
10.5(2)
Cisco/Cisco Packaged Contact Center Enterprise
10.5(2)_ES8
Cisco/Cisco Packaged Contact Center Enterprise
11.0(1)
Cisco/Cisco Packaged Contact Center Enterprise
11.0(2)
Cisco/Cisco Packaged Contact Center Enterprise
11.5(1)
Cisco/Cisco Packaged Contact Center Enterprise
11.6(1)
Cisco/Cisco Packaged Contact Center Enterprise
11.6(2)
Cisco/Cisco Packaged Contact Center Enterprise
12.0(1)
... and 40 more
Published
Nov 05, 2025
Tracked Since
Feb 18, 2026