CVE-2025-20377

MEDIUM

Cisco Unified Intelligence Center - Info Disclosure

Title source: llm
STIX 2.1

Description

A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending a valid request to a specific API endpoint within the affected system. A successful exploit could allow a low-privileged user to view sensitive information on the affected system that should be restricted. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

Scores

CVSS v3 4.3
EPSS 0.0005
EPSS Percentile 15.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (50)
Cisco/Cisco Packaged Contact Center Enterprise 10.5(1)
Cisco/Cisco Packaged Contact Center Enterprise 10.5(1)_ES7
Cisco/Cisco Packaged Contact Center Enterprise 10.5(2)
Cisco/Cisco Packaged Contact Center Enterprise 10.5(2)_ES8
Cisco/Cisco Packaged Contact Center Enterprise 11.0(1)
Cisco/Cisco Packaged Contact Center Enterprise 11.0(2)
Cisco/Cisco Packaged Contact Center Enterprise 11.5(1)
Cisco/Cisco Packaged Contact Center Enterprise 11.6(1)
Cisco/Cisco Packaged Contact Center Enterprise 11.6(2)
Cisco/Cisco Packaged Contact Center Enterprise 12.0(1)
... and 40 more
Published Nov 05, 2025
Tracked Since Feb 18, 2026