CVE-2025-20139

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 2, 2025
Updated: Apr 7, 2025
CWE ID 185

Summary

CVE-2025-20139 is a denial-of-service vulnerability affecting Cisco Enterprise Chat and Email (ECE). The issue stems from improper input validation in chat entry points. An unauthenticated, remote attacker can exploit this flaw by sending malicious requests, leading to the application becoming unresponsive and causing a denial-of-service condition. The affected application may not recover on its own, necessitating manual intervention from an administrator to restore services.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Cisco Enterprise Chat and Email

Affected Vendors

  • Cisco