Skip to content

Cisco CCX Vulnerabilities Open Door to Remote Attacks

Esecurityplanet Ken Underhill November 5, 2025

Critical flaws in Cisco’s Unified CCX platform allow remote attackers to execute malicious code and gain full control of center systems.

Cisco has disclosed two critical vulnerabilities affecting its Unified Center Express (CCX) platform that could allow unauthenticated remote attackers to execute malicious code and gain elevated privileges.

The flaws present risks to organizations relying on CCX for customer support and call center operations.

The first vulnerability, CVE-2025-20354 , carries a CVSS severity score of 9.8, and is a critical remote code execution (RCE) flaw.

It resides in the Java Remote Method Invocation (RMI) process used by Unified CCX.

Improper authentication validation allows attackers to upload arbitrary files through the RMI service without any authentication.

Once exploited, this flaw enables attackers to execute system commands with root privileges, giving them complete control over the affected server.

This level of access could allow adversaries to install backdoors, steal sensitive customer data, or deploy ransomware across center networks.

Cisco confirmed that the root cause lies in flawed authentication mechanisms that fail to properly verify user identities during remote interactions.

The second flaw, CVE-2025-20358 , carries a CVSS score of 9.4 and targets the Cisco Unified CCX Editor application.

This vulnerability allows attackers to perform an authentication bypass by redirecting the login flow to a malicious server.

When successful, the CCX Editor falsely recognizes the attacker’s server as legitimate, granting administrative access.

Once inside, attackers can create, modify, or execute arbitrary scripts as internal non-root users.

This exploit effectively allows malicious actors to manipulate call-handling workflows, inject custom scripts, or disrupt center operations.

Together, the two vulnerabilities form a powerful attack chain — one that begins with unauthenticated access and ends with persistent administrative control.

This sequence enables attackers to escalate privileges, execute code remotely, and maintain long-term presence within the target environment.

According to Cisco’s advisory, both vulnerabilities affect all Unified CCX configurations, regardless of deployment settings or scale.

That includes on-premises and hybrid installations. However, other Cisco products, such as Unified Center Enterprise (CCE) and Packaged Center Enterprise (PCCE), remain unaffected.

Organizations using Unified CCX version 12.5 SU3 and earlier must upgrade immediately to version 12.5 SU3 ES07.

Those running version 15.0 should install version 15.0 ES01. Cisco has released patches addressing both vulnerabilities and confirmed that no workarounds are available.

Failure to apply these updates leaves systems open to complete compromise, as attackers could exploit these flaws to seize control of customer service operations, intercept customer communications, or deploy additional payloads throughout an enterprise network.

The CCX vulnerabilities highlight an ongoing trend in which attackers target high-value, communication-centered systems that manage sensitive customer data.

center infrastructure often integrates deeply with CRM platforms, authentication servers, and enterprise networks, making it an attractive target for cybercriminals.

The discovery of these flaws also underscores the importance of secure software design and continuous patch management in enterprise environments.

Systems that rely on remote method invocation, authentication handoffs, or multi-layered workflows must undergo frequent security reviews to mitigate emerging risks.

To reduce the risk posed by these critical Cisco Unified CCX vulnerabilities, organizations should take immediate action to strengthen their security posture, including:

As attackers increasingly target interconnected enterprise tools, maintaining an effective patch management program and enforcing layered security controls remain critical parts of cyber resilience.

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

Check Point shows how generative AI accelerates XLoader analysis, uncovering real C2s and enabling faster, smarter malware defense.

A critical React Native flaw exposes millions of developers to remote code attacks.

European authorities dismantled a €600 million crypto fraud network in a coordinated international operation.

Scattered LAPSUS$ Hunters unites major cybercrime groups to launch sophisticated, multi-stage attacks on global enterprises.

Extracted Entities

Attack Types (2)

Companies (1)

Malware (1)