CVE-2025-20278 | Cisco Finesse CLI command command injection (cisco-sa-vos-command-inject-65s2UCYy / EUVD-2025-16884)
A vulnerability, which was classified as critical, has been found in Cisco Finesse, SocialMiner, Unified Communications Manager, Unified Communications Manager IM and Presence Service, Unified Contact Center Express, Unified Intelligence Center, Unity Connection and Virtualized Voice Browser. This issue affects some unknown processing of the component CLI. The manipulation of the argument command leads to command injection.
The identification of this vulnerability is CVE-2025-20278. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.