CVE-2025-20278

MEDIUM EPSS 5.1%
Published Jun 4, 20251y ago · Modified Jun 17, 20261w ago
6.7 CVSS 3.1
Medium
Find Similar
Published Jun 4, 2025 1y ago
Last Modified Jun 17, 2026 1w ago

Description

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.

CVSS Details

Base Score
6.7
Exploitability
0.8
Impact
5.9
Vector string
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required High
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
5.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available

Weaknesses 1

CWE-77 Command Injection Injection

Affected Products 193

VendorProductVersionRange
ciscofinesse10.5\(1\)any
ciscofinesse10.5\(1\)_es1any
ciscofinesse10.5\(1\)_es2any
ciscofinesse10.5\(1\)_es3any
ciscofinesse10.5\(1\)_es4any
ciscofinesse10.5\(1\)_es5any
ciscofinesse10.5\(1\)_es6any
ciscofinesse10.5\(1\)_es7any
ciscofinesse10.5\(1\)_es8any
ciscofinesse10.5\(1\)_es9any
ciscofinesse10.5\(1\)_es10any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.0\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.5\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)any
ciscofinesse11.6\(1\)_fipsany
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.0\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(1\)any
ciscofinesse12.5\(2\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(1\)any
ciscofinesse12.6\(2\)any
ciscofinesse12.6\(2\)any
ciscofinesse12.6\(2\)any
ciscofinesse12.6\(2\)any
ciscofinesse12.6\(2\)any
ciscofinesse12.6\(2\)any
ciscosocialminer10.5\(1\)any
ciscosocialminer10.6\(1\)any
ciscosocialminer10.6\(2\)any
ciscosocialminer11.0\(1\)any
ciscosocialminer11.5\(1\)any
ciscosocialminer11.5\(1\)su1any
ciscosocialminer11.6\(1\)any
ciscosocialminer11.6\(2\)any
ciscosocialminer12.0\(1\)any
ciscosocialminer12.0\(1\)es02any
ciscosocialminer12.0\(1\)es03any
ciscosocialminer12.0\(1\)es04any
ciscosocialminer12.5\(1\)any
ciscosocialminer12.5\(1\)es01any
ciscosocialminer12.5\(1\)su1any
ciscosocialminer12.5\(1\)su2any
ciscosocialminer12.5\(1\)su3any
ciscounified_communications_manager12.5\(1\)any
ciscounified_communications_manager12.5\(1\)su1any
ciscounified_communications_manager12.5\(1\)su2any
ciscounified_communications_manager12.5\(1\)su3any
ciscounified_communications_manager12.5\(1\)su4any
ciscounified_communications_manager12.5\(1\)su5any
ciscounified_communications_manager12.5\(1\)su6any
ciscounified_communications_manager12.5\(1\)su7any
ciscounified_communications_manager12.5\(1\)su7aany
ciscounified_communications_manager12.5\(1\)su8any
ciscounified_communications_manager12.5\(1\)su8aany
ciscounified_communications_manager12.5\(1\)su9any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su1any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su2any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su3any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su4any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su5any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su6any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su7any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su8any
ciscounified_communications_manager_im_and_presence_service12.5\(1\)su9any
ciscounified_contact_center_express8.5\(1\)any
ciscounified_contact_center_express9.0\(2\)su3es04any
ciscounified_contact_center_express10.0\(1\)su1any
ciscounified_contact_center_express10.0\(1\)su1es04any
ciscounified_contact_center_express10.5\(1\)any
ciscounified_contact_center_express10.5\(1\)su1any
ciscounified_contact_center_express10.5\(1\)su1es10any
ciscounified_contact_center_express10.6\(1\)any
ciscounified_contact_center_express10.6\(1\)su1any
ciscounified_contact_center_express10.6\(1\)su2any
ciscounified_contact_center_express10.6\(1\)su2es04any
ciscounified_contact_center_express10.6\(1\)su3any
ciscounified_contact_center_express10.6\(1\)su3es01any
ciscounified_contact_center_express10.6\(1\)su3es02any
ciscounified_contact_center_express10.6\(1\)su3es03any
ciscounified_contact_center_express11.0\(1\)su1any
ciscounified_contact_center_express11.0\(1\)su1es02any
ciscounified_contact_center_express11.0\(1\)su1es03any
ciscounified_contact_center_express11.5\(1\)es01any
ciscounified_contact_center_express11.5\(1\)su1any
ciscounified_contact_center_express11.5\(1\)su1es01any
ciscounified_contact_center_express11.5\(1\)su1es02any
ciscounified_contact_center_express11.5\(1\)su1es03any
ciscounified_contact_center_express11.6\(1\)any
ciscounified_contact_center_express11.6\(1\)es01any
ciscounified_contact_center_express11.6\(1\)es02any
ciscounified_contact_center_express11.6\(2\)any
ciscounified_contact_center_express11.6\(2\)es01any
ciscounified_contact_center_express11.6\(2\)es02any
ciscounified_contact_center_express11.6\(2\)es03any
ciscounified_contact_center_express11.6\(2\)es04any
ciscounified_contact_center_express11.6\(2\)es05any
ciscounified_contact_center_express11.6\(2\)es06any
ciscounified_contact_center_express11.6\(2\)es07any
ciscounified_contact_center_express11.6\(2\)es08any
ciscounified_contact_center_express12.0\(1\)any
ciscounified_contact_center_express12.0\(1\)es01any
ciscounified_contact_center_express12.0\(1\)es02any
ciscounified_contact_center_express12.0\(1\)es03any
ciscounified_contact_center_express12.0\(1\)es04any
ciscounified_contact_center_express12.5\(1\)any
ciscounified_contact_center_express12.5\(1\)_su01_es01any
ciscounified_contact_center_express12.5\(1\)_su01_es02any
ciscounified_contact_center_express12.5\(1\)_su01_es03any
ciscounified_contact_center_express12.5\(1\)_su02_es01any
ciscounified_contact_center_express12.5\(1\)_su02_es02any
ciscounified_contact_center_express12.5\(1\)_su02_es03any
ciscounified_contact_center_express12.5\(1\)_su02_es04any
ciscounified_contact_center_express12.5\(1\)_su03_es01any
ciscounified_contact_center_express12.5\(1\)_su03_es02any
ciscounified_contact_center_express12.5\(1\)_su03_es03any
ciscounified_contact_center_express12.5\(1\)_su03_es04any
ciscounified_contact_center_express12.5\(1\)_su03_es05any
ciscounified_contact_center_express12.5\(1\)_su03_es06any
ciscounified_contact_center_express12.5\(1\)es01any
ciscounified_contact_center_express12.5\(1\)es02any
ciscounified_contact_center_express12.5\(1\)es03any
ciscounified_contact_center_express12.5\(1\)su1any
ciscounified_contact_center_express12.5\(1\)su2any
ciscounified_contact_center_express12.5\(1\)su3any
ciscounified_intelligence_center* <12.6\(2\)es_04
ciscounity_connection12.5\(1\)any
ciscounity_connection12.5\(1\)su1any
ciscounity_connection12.5\(1\)su2any
ciscounity_connection12.5\(1\)su3any
ciscounity_connection12.5\(1\)su4any
ciscounity_connection12.5\(1\)su5any
ciscounity_connection12.5\(1\)su6any
ciscounity_connection12.5\(1\)su7any
ciscounity_connection12.5\(1\)su8any
ciscounity_connection12.5\(1\)su8aany
ciscounity_connection12.5\(1\)su9any
ciscovirtualized_voice_browser* <12.6\(2\)es06

References 1

  • sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy
    Vendor Advisory

Remediation

No remediation data recorded yet

Check vendor advisories and the NVD entry for patch availability.