VendorsCiscounified_communications_managerall versions
Vulnerabilities

Cisco Unified Communications Manager

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

239CVEs
CVE-2019-12716
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
Published 2019-10-02 · Modified
6.1EPSS 0.011
CVE-2022-20788
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2022-04-21 · Modified
6.1EPSS 0.008
CVE-2020-3346
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
Published 2020-08-17 · Modified
6.1EPSS 0.008
CVE-2021-1380
Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities
Published 2021-04-08 · Modified
6.1EPSS 0.008
CVE-2021-1407
Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities
Published 2021-04-08 · Modified
6.1EPSS 0.008
CVE-2021-1408
Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities
Published 2021-04-08 · Modified
6.1EPSS 0.008
CVE-2021-1409
Cisco Unified Communications Products Cross-Site Scripting Vulnerabilities
Published 2021-04-08 · Modified
6.1EPSS 0.008
CVE-2020-3282
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2020-07-02 · Modified
6.1EPSS 0.008
CVE-2015-0749
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
Published 2020-02-19 · Modified
6.1EPSS 0.008
CVE-2022-20800
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2022-07-06 · Modified
6.1EPSS 0.008
CVE-2022-20815
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2022-07-06 · Modified
6.1EPSS 0.008
CVE-2023-20242
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published 2023-08-16 · Modified
6.1EPSS 0.005
CVE-2024-20488
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
Published 2024-08-21 · Analyzed
6.1EPSS 0.004
CVE-2024-20511
Cisco Unified Communications Manager Cross-Site Scripting Vulnerability
Published 2024-11-06 · Analyzed
6.1EPSS 0.003
CVE-2014-0686
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
Published 2014-02-04 · Modified
6.0EPSS 0.003
CVE-2014-3317
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.
Published 2014-07-14 · Modified
5.5EPSS 0.026
CVE-2014-3292
The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to (1) read or (2) delete arbitrary files via a crafted URL, aka Bug IDs CSCuo17302 and CSCuo17199.
Published 2014-06-10 · Modified
5.5EPSS 0.015
CVE-2018-0340
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of certain parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting certain malicious code. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvj00512.
Published 2018-06-07 · Modified
5.4EPSS 0.013
CVE-2018-15403
Multiple Cisco Unified Communications Products Open Redirect Vulnerability
Published 2018-10-05 · Modified
5.4EPSS 0.012
CVE-2017-3888
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability affects Cisco Unified Communications Manager with a default configuration running an affected software release with the attacker authenticated as the administrative user. More Information: CSCvc83712. Known Affected Releases: 12.0(0.98000.452). Known Fixed Releases: 12.0(0.98000.750) 12.0(0.98000.708) 12.0(0.98000.707) 12.0(0.98000.704) 12.0(0.98000.554) 12.0(0.98000.546) 12.0(0.98000.543) 12.0(0.98000.248) 12.0(0.98000.244) 12.0(0.98000.242).
Published 2017-04-07 · Modified
5.4EPSS 0.012
CVE-2011-4019
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.
Published 2012-05-03 · Modified
5.4EPSS 0.011
CVE-2017-12357
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvf79346.
Published 2017-11-30 · Modified
5.4EPSS 0.009
CVE-2017-3874
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.507) 11.0(1.23900.5) 11.0(1.23900.3) 10.5(2.15900.2).
Published 2017-03-17 · Modified
5.4EPSS 0.009
CVE-2020-3420
Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability
Published 2024-11-18 · Analyzed
5.4EPSS 0.004
CVE-2018-0105
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker to view data library information. Cisco Bug IDs: CSCvf20269.
Published 2018-01-18 · Modified
5.3EPSS 0.017
CVE-2018-0198
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables. An attacker could exploit this vulnerability by browsing to a specific URL. A successful exploit could allow the attacker to view data library information. Cisco Bug IDs: CSCvh66592.
Published 2018-03-27 · Modified
5.3EPSS 0.017
CVE-2022-20752
Cisco Unified Communications Products Timing Attack Vulnerability
Published 2022-07-06 · Modified
5.3EPSS 0.010
CVE-2015-6425
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.
Published 2015-12-16 · Modified
5.0EPSS 0.024
CVE-2008-2062
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsq35151.
Published 2008-06-26 · Modified
5.0EPSS 0.023
CVE-2014-0722
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allows remote attackers to cause a denial of service (performance degradation) via unspecified use of this application, aka Bug ID CSCum05347.
Published 2014-02-13 · Modified
5.0EPSS 0.019
CVE-2014-0731
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.
Published 2014-02-22 · Modified
5.0EPSS 0.019
CVE-2014-0732
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.
Published 2014-02-20 · Modified
5.0EPSS 0.018
CVE-2014-0733
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.
Published 2014-02-20 · Modified
5.0EPSS 0.018
CVE-2008-2730
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.
Published 2008-06-26 · Modified
5.0EPSS 0.017
CVE-2007-3776
Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.
Published 2007-07-15 · Modified
5.0EPSS 0.015
CVE-2014-0743
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.
Published 2014-02-27 · Modified
5.0EPSS 0.014
CVE-2013-1188
Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515.
Published 2013-05-16 · Modified
5.0EPSS 0.014
CVE-2014-0725
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to obtain sensitive information via unspecified access to a "file storage location," aka Bug ID CSCum05337.
Published 2014-02-13 · Modified
5.0EPSS 0.013
CVE-2012-0376
The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367.
Published 2012-05-03 · Modified
5.0EPSS 0.012
CVE-2014-2184
The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain sensitive information via a crafted URL, aka Bug ID CSCun74352.
Published 2014-04-29 · Modified
5.0EPSS 0.012
← Prev5 / 6Next →