Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control

🚨SEVERITY: MEDIUM β€” CVSS 6.5Security Advisory

TL;DR πŸ“Œ

  • A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific port…
  • Highest CVSS: 6.5 (Medium).
  • Check the advisory for fixed releases β€” remediation detail is in the vendor link below.
  • CVEs: CVE-2025-20242.

What it is

CVE-2025-20242 affects the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE). The flaw is a lack of proper authentication controls on a specific TCP port used by the component.

An unauthenticated, remote attacker can exploit this by sending crafted TCP data to that port on an affected device. No credentials or user interaction are required, and the attack takes place over the network rather than requiring local access.

A successful exploit lets the attacker read or modify data on the affected device. The impact is limited to confidentiality and integrity β€” Cisco’s own scoring shows no effect on availability (CVSS vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N), giving a base score of 6.5 (Medium).

Cisco Unified CCE Cloud Connect release 12.6.2 is listed as vulnerable; 12.6.1 and earlier, and 15.0.1, are listed as not vulnerable.

What to do

  • If you are running Cisco Unified CCE Cloud Connect 12.6.2, migrate to a fixed release as specified in Cisco’s advisory (cisco-sa-contcent-insuffacces-ArDOVhN8).
  • There are no workarounds β€” mitigating this without upgrading is not an option, so plan the migration rather than relying on compensating controls.
  • Confirm your Cloud Connect version and configuration against the advisory’s Fixed Releases table, since Cisco notes that 12.6.1 and earlier, and 15.0.1, are not affected.
  • Since the access path is a specific TCP port reachable without authentication, review network exposure of Cloud Connect devices and ensure the relevant port is not reachable from untrusted networks while the upgrade is scheduled.
  • Check current hardware and software configurations for compatibility with the target release before upgrading, and engage Cisco TAC if that isn’t clear.

For leadership 🧭

Executive summary. A contact centre component that many organisations expose for cloud integration can be read from or written to by anyone who can reach the right TCP port, with no login required. There’s no workaround, so affected 12.6.2 deployments need a migration plan rather than a quick fix.

Why it matters:

  • The flaw sits in Cloud Connect, the CCE component that bridges on-premises contact centre infrastructure to Cisco’s cloud services, making it a likely candidate for broader network reachability
  • Exploitation needs no credentials and no user interaction β€” just crafted TCP data sent to the affected port, over the network
  • A successful attacker can both read and modify data on the device, affecting confidentiality and integrity of contact centre data
  • Only release 12.6.2 is listed as vulnerable, with no workaround available, so remediation depends entirely on migrating to a fixed release

Now / Next / Later:

  • Now: Identify every Cisco Unified CCE Cloud Connect device in your estate and check its release version against the advisory’s table to see if it’s running 12.6.2.
  • Next: Restrict network reachability to the affected TCP port on any 12.6.2 Cloud Connect devices from untrusted networks while you schedule the migration, since no workaround exists to fix the flaw itself.
  • Later: Migrate 12.6.2 deployments to a fixed release, verifying hardware and configuration compatibility beforehand, and build version tracking for Cloud Connect into routine patch reviews given this component’s exposure to cloud-facing traffic.

Source