Vulnslist

find the latest Cisco vulnerabilities

Cisco Enterprise Chat and Email Denial of Service Vulnerability

cisco-sa-ece-dos-tC6m9GZ8 · High · Published · Updated

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-dos-tC6m9GZ8

Workarounds

There are no workarounds that address this vulnerability.

CVEsCVE-2025-20139
Cisco Bug IDsCSCwm08282
CVSS ScoreBase 7.5
Base 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:X/RL:X/RC:X
Product Names From Source
Cisco Enterprise Chat and Email

Related Products

Product CVE Evidence
Cisco RV Series Routers CVE-2025-20139 Cisco OpenVuln
Cisco Nexus Dashboard CVE-2025-20139 Cisco OpenVuln
Cisco Catalyst PON Series Switches CVE-2025-20139 Cisco OpenVuln
Cisco Enterprise Chat and Email CVE-2025-20139 Cisco OpenVuln