A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device.
References
| Link | Resource |
|---|---|
| https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuis-ssrf-JSuDjeV | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
History
No history.
Information
Published : 2025-07-16 17:15
Updated : 2025-07-22 14:40
NVD link : CVE-2025-20288
Mitre link : CVE-2025-20288
CVE.ORG link : CVE-2025-20288
JSON object : View
Products Affected
cisco
- unified_contact_center_express
- unified_intelligence_center
CWE
CWE-918
Server-Side Request Forgery (SSRF)
