The advisory's indicator of compromise for CVE-2025-20309 is a successful root SSH login recorded in /var/log/active/syslog/secure.

Checked 2026-09-25

Vendor
Cisco
Product
Unified Communications Manager
Subsystem
PSIRT advisory
Deployment
on-premises
Region
not restricted
Release range
ES 15.0.1.13010-1 through 15.0.1.13017-1
Checked
2026-09-25

Sources

Cite this note

APA

WarmTransfer. (2026, September 25). Unified CM security hardening: source note cucm-security-hardening-cve-2025-20309-ioc. WarmTransfer. https://warmtransfer.net/knowledge/claims/cucm-security-hardening-cve-2025-20309-ioc

BibTeX

@misc{warmtransfer-claim-cucm-security-hardening-cve-2025-20309-ioc,
  title  = {Unified CM security hardening: source note cucm-security-hardening-cve-2025-20309-ioc},
  author = {{WarmTransfer}},
  year   = {2026},
  url    = {https://warmtransfer.net/knowledge/claims/cucm-security-hardening-cve-2025-20309-ioc},
  note   = {Source note cucm-security-hardening-cve-2025-20309-ioc, checked 2026-09-25}
}

Read in context