Cisco UIC: Authenticated Remote Privilege Escalation via API
CVE-2025-20113 Published on May 21, 2025
Cisco Unified Intelligence Center Privilege Escalation Vulnerability
A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system.
This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An attacker could exploit this vulnerability by submitting a crafted API or HTTP request to an affected system. A successful exploit could allow the attacker to access, modify, or delete data beyond the sphere of their intended access level, including obtaining potentially sensitive information stored in the system.
Vulnerability Analysis
CVE-2025-20113 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and no impact on availability.
Weakness Type
Client-Side Enforcement of Server-Side Security
The software is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. When the server relies on protection mechanisms placed on the client side, an attacker can modify the client-side behavior to bypass the protection mechanisms resulting in potentially unexpected interactions between the client and server. The consequences will vary, depending on what the mechanisms are trying to protect.
Products Associated with CVE-2025-20113
stack.watch emails you whenever new vulnerabilities are published in Cisco Unified Intelligence Center or Cisco Unified Contact Center Express. Just hit a watch button to start following.
Affected Versions
Cisco Unified Contact Center Express:- Version 10.6(1) is affected.
- Version 10.5(1)SU1 is affected.
- Version 10.6(1)SU3 is affected.
- Version 12.0(1) is affected.
- Version 10.0(1)SU1 is affected.
- Version 10.6(1)SU1 is affected.
- Version 11.0(1)SU1 is affected.
- Version 11.5(1)SU1 is affected.
- Version 10.5(1) is affected.
- Version 11.6(1) is affected.
- Version 11.6(2) is affected.
- Version 12.5(1) is affected.
- Version 12.5(1)SU1 is affected.
- Version 12.5(1)SU2 is affected.
- Version 12.5(1)SU3 is affected.
- Version 12.5(1)_SU03_ES01 is affected.
- Version 12.5(1)_SU03_ES02 is affected.
- Version 12.5(1)_SU02_ES03 is affected.
- Version 12.5(1)_SU02_ES04 is affected.
- Version 12.5(1)_SU02_ES02 is affected.
- Version 12.5(1)_SU01_ES02 is affected.
- Version 12.5(1)_SU01_ES03 is affected.
- Version 12.5(1)_SU02_ES01 is affected.
- Version 11.6(2)ES07 is affected.
- Version 11.6(2)ES08 is affected.
- Version 12.5(1)_SU01_ES01 is affected.
- Version 12.0(1)ES04 is affected.
- Version 12.5(1)ES02 is affected.
- Version 12.5(1)ES03 is affected.
- Version 11.6(2)ES06 is affected.
- Version 12.5(1)ES01 is affected.
- Version 12.0(1)ES03 is affected.
- Version 12.0(1)ES01 is affected.
- Version 11.6(2)ES05 is affected.
- Version 12.0(1)ES02 is affected.
- Version 11.6(2)ES04 is affected.
- Version 11.6(2)ES03 is affected.
- Version 11.6(2)ES02 is affected.
- Version 11.6(2)ES01 is affected.
- Version 10.6(1)SU3ES03 is affected.
- Version 11.0(1)SU1ES03 is affected.
- Version 10.6(1)SU3ES01 is affected.
- Version 10.5(1)SU1ES10 is affected.
- Version 10.0(1)SU1ES04 is affected.
- Version 11.5(1)SU1ES03 is affected.
- Version 11.6(1)ES02 is affected.
- Version 11.5(1)ES01 is affected.
- Version 9.0(2)SU3ES04 is affected.
- Version 10.6(1)SU2 is affected.
- Version 10.6(1)SU2ES04 is affected.
- Version 11.6(1)ES01 is affected.
- Version 10.6(1)SU3ES02 is affected.
- Version 11.5(1)SU1ES02 is affected.
- Version 11.5(1)SU1ES01 is affected.
- Version 8.5(1) is affected.
- Version 11.0(1)SU1ES02 is affected.
- Version 12.5(1)_SU03_ES03 is affected.
- Version 12.5(1)_SU03_ES04 is affected.
- Version 12.5(1)_SU03_ES05 is affected.
- Version 12.5(1)_SU03_ES06 is affected.
- Version 11.6(1) is affected.
- Version 10.5(1) is affected.
- Version 11.0(1) is affected.
- Version 11.5(1) is affected.
- Version 12.0(1) is affected.
- Version 12.5(1) is affected.
- Version 11.0(2) is affected.
- Version 12.6(1) is affected.
- Version 12.5(1)SU is affected.
- Version 12.6(1)_ET is affected.
- Version 12.6(1)_ES05_ET is affected.
- Version 11.0(3) is affected.
- Version 12.6(2) is affected.
- Version 12.6(2)_504_Issue_ET is affected.
- Version 12.6.1_ExcelIssue_ET is affected.
- Version 12.6(2)_Permalink_ET is affected.
- Version 12.6.2_CSCwk19536_ET is affected.
- Version 12.6.2_CSCwm96922_ET is affected.
- Version 12.5(2)ET_CSCwi79933 is affected.
- Version 12.6.2_CSCwn48501_ET is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.