Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Ransomware Gang Hunter International says it’s shut down

Eternal chemicals can affect the development of the brain in men

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Steal User Assets

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A critical Cisco vulnerability in unified CM grants root access through static credentials
Identity

A critical Cisco vulnerability in unified CM grants root access through static credentials

userBy userJuly 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 3, 2025Ravi LakshmananVulnerability/Network Security

Critical Cisco Vulnerabilities

Cisco has released security updates to address the maximum focus security flaws in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).

The CVSS score for vulnerabilities tracked as CVE-2025-20309 is 10.0.

“This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development,” Cisco said in an advisory released Wednesday.

“Attackators can exploit this vulnerability by logging in to an affected system using their account. An attacker can now log in to an affected system and run arbitrary commands as the root user.”

Such hardcoded credentials usually come from testing or quick fixes in development, but should not enter a live system. Tools such as Unified CM, which handles voice calls and communications across the company, Root Access allows attackers to delve deeper into the network, listen to calls, and change how users log in.

Cybersecurity

The Networking Equipment Major said no evidence of exploited defects found in the wild and was discovered during internal security testing.

CVE-2025-20309 affects unified CM and Unified CM SME versions 15.0.1.13010-1 to 15.0.1.13017-1 regardless of device configuration.

Cisco has released defect-related compromise (IOC) metrics, saying that successful exploitation will result in the root user being logged into the root user’s “/log/active/syslog/secure”. The logs can be obtained by running the following command from the command line interface –

CUCM1# Get file Activelog syslog/secure

This development comes a few days after fixing two security flaws: Identity Services Engine and ISE Passive Identity Connector (CVE-2025-20281 and CVE-2025-20282).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenai blames Robinhood’s “Openai Tokens”
Next Article San Antonio and Austin are fused into one giant megalegion
user
  • Website

Related Posts

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Steal User Assets

July 3, 2025

The Hidden Weaknesses in AI SOC Tools that No One Talks About

July 3, 2025

Chinese hackers abuse Ivanti CSA Zero Day in attacks on French government, communications

July 3, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Ransomware Gang Hunter International says it’s shut down

Eternal chemicals can affect the development of the brain in men

Over 40 Malicious Firefox Extensions Target Cryptocurrency Wallets, Steal User Assets

The British Space Agency mission is set to clean up space debris

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Meta’s Secret Weapon: The Superintelligence Unit That Could Change Everything 

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

The Digital Twin Revolution: Reshaping Industry 4.0

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.