Cisco Warns Of Critical Bug In Unified Communications Manager

Bug, which scores 10 for severity, only affected a limited number of Engineering Special versions

Cisco has reported a critical vulnerability (CVSS score of 10.0) in its Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) products.

In an advisory, Cisco said the flaw (CVE-2025-20309) concerns static, unchangeable SSH credentials for the root account, which were created for development use but were not removed prior to release.

A remote unauthenticated attacker could exploit this bug to log in as root and execute arbitrary commands, giving them full control over the system and allowing them to exfiltrate data or use the compromised device as a srpingboard for further attacks.

Fortunately, the glitch only affects specific Engineering Special (ES) releases of Cisco Unified CM and Unified CM SME: versions 15.0.1.13010-1 to 15.0.1.13017-1. These are limited fix releases distributed only by the Cisco Technical Assistance Center (TAC) and made available to customers who require the latest fixes and features. The number of affected customers is therefore likely to be small. Other releases, including service updates, are not vulnerable.

Cisco’s Product Security Incident Response Team (PSIRT) has said it is not aware of any malicious exploitation of this vulnerability, which was discovered during internal security testing.

Given the severity of the bug, affected users should act swiftly to upgrade to the latest software release 15SU3 (July 2025) or apply a patch provided by Cisco. There are no workarounds available for this vulnerability.

Cisco advises customers with service contracts to obtain updates through their usual channels, while other affected users should contact Cisco TAC for assistance.

This is the second critical vulnerability announced by Cisco in seven days. Last week the company alerted customers of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) of a bug that could allow a remote attacker to issue commands on the underlying operating system as root.

This article originally appeared on our sister site Computing.