Source note · Unified CM security hardening
CVE-2025-20309 (cisco-sa-cucm-ssh-m4UBdpE7) is a static root SSH credential in Unified CM and Unified CM SME Engineering Special releases 15.0.1.13010-1 through 15.0.1.13017-1. It applies regardless of device configuration and has a CVSS 3.1 base score of 10.0.
Checked 2026-09-25
- Vendor
- Cisco
- Product
- Unified Communications Manager
- Subsystem
- PSIRT advisory
- Deployment
- on-premises
- Region
- not restricted
- Release range
- ES 15.0.1.13010-1 through 15.0.1.13017-1
- Checked
- 2026-09-25
Sources
- Cisco Unified Communications Manager Static SSH Credentials Vulnerability (cisco-sa-cucm-ssh-m4UBdpE7) — Cisco PSIRT · tier 2 current vendor documentation · Advisory > Summary; Affected Products
Cite this note
APA
WarmTransfer. (2026, September 25). Unified CM security hardening: source note cucm-security-hardening-cve-2025-20309-scope. WarmTransfer. https://warmtransfer.net/knowledge/claims/cucm-security-hardening-cve-2025-20309-scope
BibTeX
@misc{warmtransfer-claim-cucm-security-hardening-cve-2025-20309-scope,
title = {Unified CM security hardening: source note cucm-security-hardening-cve-2025-20309-scope},
author = {{WarmTransfer}},
year = {2026},
url = {https://warmtransfer.net/knowledge/claims/cucm-security-hardening-cve-2025-20309-scope},
note = {Source note cucm-security-hardening-cve-2025-20309-scope, checked 2026-09-25}
}