{"id":676,"date":"2025-07-03T07:43:31","date_gmt":"2025-07-03T05:43:31","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=676"},"modified":"2025-07-03T07:43:31","modified_gmt":"2025-07-03T05:43:31","slug":"critical-cisco-vulnerability-in-unified-cm-grants-root-access-via-static-credentials","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2025\/07\/03\/critical-cisco-vulnerability-in-unified-cm-grants-root-access-via-static-credentials\/","title":{"rendered":"Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Cisco has released security updates to address a maximum-severity security flaw in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) that could permit an attacker to login to a susceptible device as the root user, allowing them to gain elevated privileges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vulnerability, tracked as&nbsp;<strong>CVE-2025-20309<\/strong>, carries a CVSS score of 10.0.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development,&#8221; Cisco&nbsp;<a href=\"https:\/\/sec.cloudapps.cisco.com\/security\/center\/content\/CiscoSecurityAdvisory\/cisco-sa-cucm-ssh-m4UBdpE7\" rel=\"noreferrer noopener\" target=\"_blank\">said<\/a>&nbsp;in an advisory released Wednesday.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2025\/07\/03\/critical-cisco-vulnerability-in-unified-cm-grants-root-access-via-static-credentials\/\" target=\"_self\"><a href=\"https:\/\/thehackernews.com\/2025\/07\/critical-cisco-vulnerability-in-unified.html\">Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials<\/a><span class=\"screen-reader-text\">: Critical Cisco Vulnerability in Unified CM Grants Root Access via Static Credentials<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>Cisco has released security updates to address a maximum-severity security flaw in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) that could permit an attacker to login to a susceptible device as the root user, allowing them to gain elevated privileges. The vulnerability,&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[40],"class_list":["post-676","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-40"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/676","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=676"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/676\/revisions"}],"predecessor-version":[{"id":677,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/676\/revisions\/677"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=676"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=676"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=676"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}