Vulnslist

find the latest Cisco vulnerabilities

CVE-2025-20139

A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input to chat entry points. An attacker could exploit this vulnerability by sending malicious requests to a messaging chat entry point in the affected application. A successful exploit could allow the attacker to cause the application to stop responding, resulting in a DoS condition. The application may not recover on its own and may need an administrator to manually restart services to recover.

SeverityHIGH
CVSS7.5
CWECWE-185
KEV
Published
Modified

Related Products

Product Advisory
Cisco RV Series Routers cisco-sa-ece-dos-tC6m9GZ8
Cisco Nexus Dashboard cisco-sa-ece-dos-tC6m9GZ8
Cisco Catalyst PON Series Switches cisco-sa-ece-dos-tC6m9GZ8
Cisco Enterprise Chat and Email cisco-sa-ece-dos-tC6m9GZ8