{
  "document" : {
    "aggregate_severity" : {
      "text" : "mittel"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Cisco Emergency Responder (Cisco ER) ist ein Notfall-Kommunikationssystem, das die vorhandene Notruf-Funktionalität des Cisco Unified Communications Manager erweitert.\r\nCisco Prime Collaboration ist eine Provisionierungs- Überwachungs und Managementlösung für Cisco Unified Communication Geräte.\r\nDer Cisco Unified Communications Manager (CUCM, ehemals CallManager) dient zur Gesprächsvermittlung in IP-Telefonie-Netzen.\r\nDer Cisco Unified Communications Manager (CUCM) (ehemals CallManager) dient zur Gesprächsvermittlung in IP-Telefonie-Netzen.\r\nCisco Unity Connection ist ein umfangreiches Voicemail und Integrated-Messaging- Produkt. Mit Cisco Unity Connection können Benutzer mit dem Cisco Unified Personal Communicator auf ihre Sprachnachrichten zugreifen, das Display ihres Cisco Unified IP-Telefons nutzen, um Sprachnachrichten anzuzeigen, zu sortieren und wiederzugeben, und sogar die Sprachsteuerung von Cisco Unity Connection verwenden, um auf Cisco Unified MeetingPlace Express Meetings zuzugreifen.\r\nCisco Finesse integriert traditionelle Contact-Center-Funktionen web-basiert in einen Thin-Client-Desktop.\r\nCisco Unified Contact Center Express (UCCX) ist die Kontaktverwaltung für Cisco Unified Communications.\r\nCisco Unified Intelligence Center ist eine webbasierte Berichtsanwendung für Contact Center.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein lokaler Angreifer kann eine Schwachstelle in Cisco Emergency Responder, Cisco Prime Collaboration, Cisco Unified Communications Manager (CUCM), Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Finesse, Cisco Unified Contact Center Express (UCCX) und Cisco Unified Intelligence Center ausnutzen, um seine Privilegien zu erhöhen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Linux\n- Sonstiges\n- UNIX\n- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2025-1116 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1116.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2025-1116 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1116"
    }, {
      "category" : "external",
      "summary" : "Cisco Security Advisory vom 2025-05-21",
      "url" : "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-kkhZbHR5"
    } ],
    "source_lang" : "en-US",
    "title" : "Cisco Unified Communications Produkte: Schwachstelle ermöglicht Privilegieneskalation",
    "tracking" : {
      "current_release_date" : "2025-05-21T22:00:00.000+00:00",
      "generator" : {
        "date" : "2025-05-22T09:00:05.138+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.3.12"
        }
      },
      "id" : "WID-SEC-W-2025-1116",
      "initial_release_date" : "2025-05-21T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2025-05-21T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      } ],
      "status" : "final",
      "version" : "1"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15SU2",
          "product" : {
            "name" : "Cisco Emergency Responder <15SU2",
            "product_id" : "T044063"
          }
        }, {
          "category" : "product_version",
          "name" : "15SU2",
          "product" : {
            "name" : "Cisco Emergency Responder 15SU2",
            "product_id" : "T044063-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:emergency_responder:15su2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Emergency Responder"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15",
          "product" : {
            "name" : "Cisco Finesse <15",
            "product_id" : "T044070"
          }
        }, {
          "category" : "product_version",
          "name" : "15",
          "product" : {
            "name" : "Cisco Finesse 15",
            "product_id" : "T044070-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:finesse:15"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Finesse"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15SU2",
          "product" : {
            "name" : "Cisco Prime Collaboration <15SU2",
            "product_id" : "T044064"
          }
        }, {
          "category" : "product_version",
          "name" : "15SU2",
          "product" : {
            "name" : "Cisco Prime Collaboration 15SU2",
            "product_id" : "T044064-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:prime_collaboration:15su2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Prime Collaboration"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15SU2",
          "product" : {
            "name" : "Cisco Unified Communications Manager (CUCM) <15SU2",
            "product_id" : "T044065"
          }
        }, {
          "category" : "product_version",
          "name" : "15SU2",
          "product" : {
            "name" : "Cisco Unified Communications Manager (CUCM) 15SU2",
            "product_id" : "T044065-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:unified_communications_manager:15su2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Unified Communications Manager (CUCM)"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15SU2",
          "product" : {
            "name" : "Cisco Unified Communications Manager IM & Presence Service <15SU2",
            "product_id" : "T044067"
          }
        }, {
          "category" : "product_version",
          "name" : "15SU2",
          "product" : {
            "name" : "Cisco Unified Communications Manager IM & Presence Service 15SU2",
            "product_id" : "T044067-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:unified_communications_manager_im_and_presence_service:15su2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Unified Communications Manager IM & Presence Service"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15",
          "product" : {
            "name" : "Cisco Unified Contact Center Express (UCCX) <15",
            "product_id" : "T044071"
          }
        }, {
          "category" : "product_version",
          "name" : "15",
          "product" : {
            "name" : "Cisco Unified Contact Center Express (UCCX) 15",
            "product_id" : "T044071-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:unified_contact_center_express:15"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Unified Contact Center Express (UCCX)"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15",
          "product" : {
            "name" : "Cisco Unified Intelligence Center <15",
            "product_id" : "T044072"
          }
        }, {
          "category" : "product_version",
          "name" : "15",
          "product" : {
            "name" : "Cisco Unified Intelligence Center 15",
            "product_id" : "T044072-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:unified_intelligence_center:15"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Unified Intelligence Center"
      }, {
        "branches" : [ {
          "category" : "product_version_range",
          "name" : "<15SU2",
          "product" : {
            "name" : "Cisco Unity Connection <15SU2",
            "product_id" : "T044068"
          }
        }, {
          "category" : "product_version",
          "name" : "15SU2",
          "product" : {
            "name" : "Cisco Unity Connection 15SU2",
            "product_id" : "T044068-fixed",
            "product_identification_helper" : {
              "cpe" : "cpe:/a:cisco:unity_connection:15su2"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Unity Connection"
      } ],
      "category" : "vendor",
      "name" : "Cisco"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2025-20112",
    "product_status" : {
      "known_affected" : [ "T044063", "T044065", "T044064", "T044067", "T044068" ]
    },
    "release_date" : "2025-05-21T22:00:00.000+00:00",
    "title" : "CVE-2025-20112"
  } ]
}