---
id: CVE-2025-20278
title: >-
  Cisco Unified Communications Products Command Injection Vulnerability
  (CVE-2025-20278)
summary: "A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user.\r\n\r\nThis vuln…"
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'
cvssSource: vendor
vendor: Cisco
product: Cisco Unified Communications Manager
affected:
  - unified_communications_manager
  - unified_intelligence_center
  - virtualized_voice_browser
  - finesse
  - unity_connection
  - unified_contact_center_express
  - unified_communications_manager_im_and_presence_service
  - socialminer
published: '2025-06-04'
updated: '2025-06-04'
sourceUpdated: '2025-06-04T16:00:00+00:00'
source: CSAF
sourceUrl: >-
  https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy
  - url: 'https://software.cisco.com'
tags:
  - csaf
  - vendor-advisory
  - cisco
epss: 0.00176
epssPercentile: 0.06268
ingestedAt: '2026-09-08T15:58:18.537Z'
---

## Overview

A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user.

This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerability by executing crafted commands on the CLI of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

## Vendor advisories

- **cisco-sa-vos-command-inject-65s2UCYy** · Cisco · affected: Cisco Unified Communications Manager, Cisco Unified Intelligence Center, Cisco Virtualized Voice Browser, Cisco Finesse, Cisco Unity Connection, Cisco Unified Contact Center Express, … · updated 2025-06-04 · [advisory](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vos-command-inject-65s2UCYy)

**Cisco Unified Communications Products Command Injection Vulnerability**. Released 2025-06-04.

Affected:

- Cisco Unified Communications Manager
- Cisco Unified Intelligence Center
- Cisco Virtualized Voice Browser
- Cisco Finesse
- Cisco Unity Connection
- Cisco Unified Contact Center Express
- Cisco Unified Communications Manager IM and Presence Service
- Cisco SocialMiner

## Remediation

Cisco has released software updates that address this vulnerability. https://software.cisco.com
