Cisco Unified CM Vulnerability Lets Remote Attacker Gain Root Access

Post Reply
Shane1145
Posts: 1836
Joined: Wed Sep 25, 2024 2:31 pm

Cisco Unified CM Vulnerability Lets Remote Attacker Gain Root Access

Post by Shane1145 »

A newly disclosed, critical vulnerability in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) has exposed organizations to the risk of full system compromise.

Tracked as CVE-2025-20309 and assigned a maximum CVSS score of 10.0, the flaw allows unauthenticated remote attackers to gain root access using static, hardcoded SSH credentials that were inadvertently left in production releases.

https://gbhackers.com/cisco-unified-cm-vulnerability/
Post Reply