A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.
History

Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0001}

epss

{'score': 0.00012}


Fri, 11 Jul 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco unified Contact Center Enterprise
CPEs cpe:2.3:a:cisco:unified_contact_center_enterprise:12.6\(2\)es2:*:*:*:*:*:*:*
Vendors & Products Cisco
Cisco unified Contact Center Enterprise

Wed, 21 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 21 May 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port on an affected device. A successful exploit could allow the attacker to read or modify data on the affected device.
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2025-05-21T19:00:45.204Z

Reserved: 2024-10-10T19:15:13.238Z

Link: CVE-2025-20242

cve-icon Vulnrichment

Updated: 2025-05-21T19:00:23.926Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-21T17:15:56.190

Modified: 2025-07-11T15:20:30.753

Link: CVE-2025-20242

cve-icon Redhat

No data.