CVE‑2025‑20309 is a critical vulnerability (CVSS 10.0) affecting Engineering Special (ES) versions of Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) from 15.0.1.13010‑1 to 15.0.1.13017‑1. These builds are shipped with hard-coded, non-removable root credentials, which allow for unauthenticated remote access, significantly increasing the risk of complete system compromise.
| Product | Cisco Systems |
| Date | 2025-07-04 14:18:39 |
| Information |
|
Technical Summary
The root account credentials were inadvertently left in the ES firmware intended solely for internal development use. Since these static credentials cannot be changed or deleted, an attacker can simply connect via SSH to the system with root privileges — without the need for authentication. Successful exploitation allows for arbitrary command execution, complete system compromise, and potential lateral movement within corporate voice and video infrastructures.
- Scope: Affects large-scale corporate communication infrastructures, voice, video, and messaging backends.
- Severity: Unlimited root access, total compromise, data theft, traffic interception, lateral movement within the network.
Recommendations
There are no valid workarounds for this vulnerability. The only recommended action is to apply the patches provided by Cisco without delay.
For affected ES 15.x releases: upgrade to 15SU3 (July 2025) or apply the patch file: ciscocm.CSCwp27755_D0247-1.cop.sha512
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
