A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted API requests to an affected system to execute an insecure direct object reference attack. A successful exploit could allow the attacker to access specific data that is associated with different users on the affected system.
References
| Link | Resource |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-priv-esc-3Pk96SU4 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2025-05-21 17:15
Updated : 2025-07-22 14:41
NVD link : CVE-2025-20114
Mitre link : CVE-2025-20114
CVE.ORG link : CVE-2025-20114
JSON object : View
Products Affected
cisco
- unified_contact_center_express
- unified_intelligence_center
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
