A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted API requests to an affected system to execute an insecure direct object reference attack. A successful exploit could allow the attacker to access specific data that is associated with different users on the affected system.
CVE ID: CVE-2025-20114
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vendor: Cisco
Product: Cisco Unified Contact Center Express, Cisco Unified Intelligence Center
EPSS Score: 0.04% (probability of being exploited)
EPSS Percentile: 12.33% (scored less or equal to compared to others)
EPSS Date: 2025-06-04 (when was this score calculated)