Back to overview

CVE-2025-20309

CRITICAL
10.0
CVSS 3.1
Description
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user.

Metadata

CVE ID
CVE-2025-20309
State
PUBLISHED
Assigner
cisco
Reserved
2024-10-10 19:15 UTC
Published
2025-07-02 16:39 UTC
Last updated
2026-02-26 18:27 UTC
Primary CWE
CWE-798
Use of Hard-coded Credentials
Vendor / Product
Cisco / Cisco Unified Communications Manager
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
Cisco Cisco Unified Communications Manager 15.0.1.13010-1, 15.0.1.13011-1, 15.0.1.13012-1, 15.0.1.13013-1 …
Weakness (CWE)
CWESourceDescription
CWE-798 cna Use of Hard-coded Credentials
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview