Cisco Unified Communications Manager IM & Presence Service Cross-Site Scripting Vulnerability

🚨SEVERITY: MEDIUM — CVSS 6.1Security Advisory

TL;DR 📌

  • A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could…
  • Highest CVSS: 6.1 (Medium).
  • Fix available — see the first fixed release below.
  • CVEs: CVE-2025-20330.

What it is

CVE-2025-20330 is a cross-site scripting flaw in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P). It stems from insufficient validation of user-supplied input in that interface.

The attack path requires an unauthenticated, remote attacker to persuade a user of the management interface to click a crafted link (CVSS vector confirms network access, low complexity, no privileges required, but user interaction is needed). There’s no indication an attacker can trigger this without that click.

A successful exploit lets the attacker execute arbitrary script in the context of the affected interface, or access sensitive browser-based information belonging to the user who clicked the link. This is a client-side, session-scoped impact rather than server compromise — reflected in the CVSS score of 6.1 (medium), with confidentiality and integrity impact rated low and no availability impact.

Cisco found this during internal security testing; there is no report of public exploitation.

What to do

  • Upgrade Unified CM IM&P release 15 to 15SU3, which contains the fix.
  • If running release 12.5 or 14, Cisco states these should be migrated to a fixed release — no dedicated patch is offered for those trains, and no interim fix exists within them.
  • There are no workarounds. Mitigation depends on getting to a fixed release.
  • Because exploitation depends on a user clicking a crafted link, treat this as an added reason to caution administrators and other IM&P interface users against clicking unsolicited or unexpected links, pending the upgrade.
  • Consult the advisory (cisco-sa-imp-xss-XQgu4HSG) for the linked bug ID for the most current fixed-release details, as Cisco notes this may be updated after publication.

Fixed releases

Affected release First fixed release
15 15SU3

For leadership 🧭

Executive summary. Cisco’s IM & Presence Service management interface can be tricked into running attacker-supplied script in an administrator’s browser via a crafted link, exposing session data rather than the server itself. There is no known active exploitation, so this can go through the next routine patch cycle rather than an emergency change.

Why it matters:

  • The flaw sits in the web-based management interface of Unified CM IM&P, the tool administrators use to configure presence and messaging services.
  • Exploitation needs an admin or interface user to click a crafted link — no authentication is required by the attacker, but the victim’s action is the trigger.
  • A successful attack can execute script in the interface’s context or expose sensitive browser-based session information, potentially aiding further access to the management console.
  • Releases 12.5 and 14 have no dedicated fix; Cisco’s only remedy for those trains is migration to a supported, fixed release.

Now / Next / Later:

  • Now: Identify all Unified CM IM&P instances and their release trains, and warn administrators who use the management interface not to click unsolicited or unexpected links.
  • Next: Upgrade release 15 deployments to 15SU3, and schedule migration of any 12.5 or 14 instances to a fixed release, since no patch exists for those versions.
  • Later: Track Cisco’s advisory for updates to the fixed-release table and build a standing process for applying Unified CM security fixes promptly, since no workaround exists for this class of issue.

Source