Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

“Fragile Space” exhibition highlights the dangers of space debris

Google fixes two active Chrome zero-days affecting Skia and V8

Elestor’s hydrogen-iron flow batteries have a 25-year shelf life

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » A critical Cisco vulnerability in unified CM grants root access through static credentials
Identity

A critical Cisco vulnerability in unified CM grants root access through static credentials

userBy userJuly 3, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 3, 2025Ravi LakshmananVulnerability/Network Security

Critical Cisco Vulnerabilities

Cisco has released security updates to address the maximum focus security flaws in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).

The CVSS score for vulnerabilities tracked as CVE-2025-20309 is 10.0.

“This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development,” Cisco said in an advisory released Wednesday.

“Attackators can exploit this vulnerability by logging in to an affected system using their account. An attacker can now log in to an affected system and run arbitrary commands as the root user.”

Such hardcoded credentials usually come from testing or quick fixes in development, but should not enter a live system. Tools such as Unified CM, which handles voice calls and communications across the company, Root Access allows attackers to delve deeper into the network, listen to calls, and change how users log in.

Cybersecurity

The Networking Equipment Major said no evidence of exploited defects found in the wild and was discovered during internal security testing.

CVE-2025-20309 affects unified CM and Unified CM SME versions 15.0.1.13010-1 to 15.0.1.13017-1 regardless of device configuration.

Cisco has released defect-related compromise (IOC) metrics, saying that successful exploitation will result in the root user being logged into the root user’s “/log/active/syslog/secure”. The logs can be obtained by running the following command from the command line interface –

CUCM1# Get file Activelog syslog/secure

This development comes a few days after fixing two security flaws: Identity Services Engine and ISE Passive Identity Connector (CVE-2025-20281 and CVE-2025-20282).

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenai blames Robinhood’s “Openai Tokens”
Next Article San Antonio and Austin are fused into one giant megalegion
user
  • Website

Related Posts

Google fixes two active Chrome zero-days affecting Skia and V8

March 13, 2026

9 CrackArmor flaws in Linux AppArmor allow route escalation and bypass container isolation

March 13, 2026

Authorities disrupt SocksEscort proxy botnet exploiting 369,000 IPs in 163 countries

March 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

“Fragile Space” exhibition highlights the dangers of space debris

Google fixes two active Chrome zero-days affecting Skia and V8

Elestor’s hydrogen-iron flow batteries have a 25-year shelf life

Destroying PFAS: Challenges, threats, and opportunities

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.