VulnerAlert



APPLICATION
APPS
CISCO
CLOUD
JAVA
04-06-2025 13:02
Tags
#java
#open
#nifi
#exploit
#editor
#contact
#add
#cloud
#cisco
#apps
#application
#vulnerability
#execution
Descripción
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability A vulnerability in the file opening process of Cisco (Unified CCX) could allow an unauthenticated attacker to execute arbitrary code on affected device.&nbsp;<br><br> This is due insecure deserialization Java objects by software. An exploit this persuading authenticated, local user open a crafted <em>.aef</em> file. A successful host that running editor application with privileges who launched it.<br><br> Cisco has released software updates address vulnerability. There are no workarounds vulnerability.<br><br> This advisory available at following link:<br><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-editor-rce-ezyYZte8">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-editor-rce-ezyYZte8</a><br><br> <br/>Security Impact Rating: Medium <br/>CVE: CVE-2025-20275 https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-editor-rce-ezyYZte8 CISCO
CVE-2025-20275
Link externo
Ver detalles

Fuente
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-editor-rce-ezyYZte8
Resultados similares
Coincidentes en almenos en 50% de los tags
05-06-2025
Hacker selling critical Roundcube webmail exploit as tech info disclosed Hackers are actively e...
Ver información
04-06-2025 CVE-2025-49008
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to versio...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por