VulnerAlert



CISCO
04-06-2025 21:05

CVE-2025-20277 Vulnerabilidad documentada

3.4 LOW
Tags
#exploit
#web
#nifi
#admin
#cisco
#vulnerability
#affected
#improper
#authenticated
#arbitrary
#root
#privilege
#execute
#allow
#attack
#affect
Descripción
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on affected device. To exploit this vulnerability, must have valid administrative credentials. This is due improper limitation a pathname restricted directory (path traversal). An by sending crafted web request device, followed specific command through SSH session. A successful underlying operating system device as low-privilege user. also undertake further actions elevate their privileges root.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-uccx-multi-UhOTvPGL
Referencia
Link externo
Ver detalles

Fuente
https://nvd.nist.gov/vuln/detail/CVE-2025-20277
Resultados similares
Coincidentes en almenos en 50% de los tags
04-06-2025 CVE-2025-20279
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authe...
Ver información
04-06-2025 CVE-2025-20276
A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authe...
Ver información
Icons made by Freepik from www.flaticon.com
Este Proyecto fue cofinanciado por el Consejo Nacional de Ciencia y Tecnología (CONACYT) a través del PROINNOVA 2021/2023
Proyecto realizado por