CVE-2025-20288
MEDIUM EPSS 24.1%
Published Jul 16, 202511mo ago · Modified Jun 17, 20261w ago
5.3 CVSS 3.1
Published Jul 16, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
24.1% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-918 Server-Side Request Forgery (SSRF) Validation
Affected Products 69
| Vendor | Product | Version | Range |
|---|---|---|---|
| cisco | unified_intelligence_center | 10.5\(1\) | any |
| cisco | unified_intelligence_center | 11.0\(1\) | any |
| cisco | unified_intelligence_center | 11.0\(2\) | any |
| cisco | unified_intelligence_center | 11.0\(3\) | any |
| cisco | unified_intelligence_center | 11.5\(1\) | any |
| cisco | unified_intelligence_center | 11.6\(1\) | any |
| cisco | unified_intelligence_center | 12.0\(1\) | any |
| cisco | unified_intelligence_center | 12.5\(1\) | any |
| cisco | unified_intelligence_center | 12.5\(1\)su | any |
| cisco | unified_intelligence_center | 12.6\(1\) | any |
| cisco | unified_intelligence_center | 12.6\(1\)_es05_et | any |
| cisco | unified_intelligence_center | 12.6\(1\)_et | any |
| cisco | unified_intelligence_center | 12.6\(2\) | any |
| cisco | unified_contact_center_express | 10.5\(1\) | any |
| cisco | unified_contact_center_express | 10.5\(1\)su1 | any |
| cisco | unified_contact_center_express | 10.5\(1\)su1es10 | any |
| cisco | unified_contact_center_express | 10.6\(1\) | any |
| cisco | unified_contact_center_express | 10.6\(1\)su1 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su2 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su2es04 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su3 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su3es01 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su3es02 | any |
| cisco | unified_contact_center_express | 10.6\(1\)su3es03 | any |
| cisco | unified_contact_center_express | 11.0\(1\)su1 | any |
| cisco | unified_contact_center_express | 11.0\(1\)su1es02 | any |
| cisco | unified_contact_center_express | 11.0\(1\)su1es03 | any |
| cisco | unified_contact_center_express | 11.5\(1\)es01 | any |
| cisco | unified_contact_center_express | 11.5\(1\)su1 | any |
| cisco | unified_contact_center_express | 11.5\(1\)su1es01 | any |
| cisco | unified_contact_center_express | 11.5\(1\)su1es02 | any |
| cisco | unified_contact_center_express | 11.5\(1\)su1es03 | any |
| cisco | unified_contact_center_express | 11.6\(1\) | any |
| cisco | unified_contact_center_express | 11.6\(1\)es01 | any |
| cisco | unified_contact_center_express | 11.6\(1\)es02 | any |
| cisco | unified_contact_center_express | 11.6\(2\) | any |
| cisco | unified_contact_center_express | 11.6\(2\)es01 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es02 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es03 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es04 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es05 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es06 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es07 | any |
| cisco | unified_contact_center_express | 11.6\(2\)es08 | any |
| cisco | unified_contact_center_express | 12.0\(1\) | any |
| cisco | unified_contact_center_express | 12.0\(1\)es01 | any |
| cisco | unified_contact_center_express | 12.0\(1\)es02 | any |
| cisco | unified_contact_center_express | 12.0\(1\)es03 | any |
| cisco | unified_contact_center_express | 12.0\(1\)es04 | any |
| cisco | unified_contact_center_express | 12.5\(1\) | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su01_es01 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su01_es02 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su01_es03 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su02_es01 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su02_es02 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su02_es03 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su02_es04 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es01 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es02 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es03 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es04 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es05 | any |
| cisco | unified_contact_center_express | 12.5\(1\)_su03_es06 | any |
| cisco | unified_contact_center_express | 12.5\(1\)es01 | any |
| cisco | unified_contact_center_express | 12.5\(1\)es02 | any |
| cisco | unified_contact_center_express | 12.5\(1\)es03 | any |
| cisco | unified_contact_center_express | 12.5\(1\)su1 | any |
| cisco | unified_contact_center_express | 12.5\(1\)su2 | any |
| cisco | unified_contact_center_express | 12.5\(1\)su3 | any |
References 1
- sec.cloudapps.cisco.com https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-ssrf-JSuDjeV
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.