Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability exists in the web-based management interface of Cisco Unified Intelligence Center, allowing authenticated, remote attackers to upload arbitrary files to affected devices. This issue arises from inadequate validation of uploaded files. Exploitation of this vulnerability could enable attackers to store malicious files on the system and execute arbitrary commands, with the potential to elevate privileges to root. The vulnerability also affects Cisco Unified Contact Center Express, as it includes Cisco Unified Intelligence Center in its software bundle. To exploit this vulnerability, an attacker must have valid credentials for a user account with at least the Report Designer role.

Impact

Successful exploitation allows for arbitrary file uploads, execution of arbitrary commands on the operating system, and elevation of privileges to root.

Remediation

Cisco has released software updates that address this vulnerability. Customers with service contracts should obtain these updates through their usual channels. For those without service contracts, contact the Cisco Technical Assistance Center (TAC) for assistance.

Added: Jul 16, 2025, 5:46 PM
Updated: Jul 16, 2025, 5:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
10.0
exploitability
4.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.