Content Description:
Forwarded from Taiwan Computer Emergency Response Team/Coordination Center TWCERTCC-200-202507-00000003
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Edition (Unified CM SME) are Cisco's unified communications platforms, primarily supporting voice, video, messaging, and collaboration functions.
Recently, Cisco issued a major security vulnerability announcement (CVE-2025-20309, CVSS: 10.0). This vulnerability stems from a default static certificate built into the product, which corresponds to a root account that is present by default and cannot be modified or deleted by the user. This vulnerability may allow unauthenticated remote attackers to log in to affected devices with root privileges and execute arbitrary commands.
Affected Platforms:
Suggested Measures:
References:
Computer and Communications Center
Network Systems Division Respectfully