VendorsCiscounified_communications_manager_im_and_presence_serviceany version
Vulnerabilities

Cisco Unified Communications Manager any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2017-12337
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration Deployment (PCD) migration is performed on an affected device. When a refresh upgrade or PCD migration is completed successfully, an engineering flag remains enabled and could allow root access to the device with a known password. If the vulnerable device is subsequently upgraded using the standard upgrade method to an Engineering Special Release, service update, or a new major release of the affected product, this vulnerability is remediated by that action. Note: Engineering Special Releases that are installed as COP files, as opposed to the standard upgrade method, do not remediate this vulnerability. An attacker who can access an affected device over SFTP while it is in a vulnerable state could gain root access to the device. This access could allow the attacker to compromise the affected system completely. Cisco Bug IDs: CSCvg22923, CSCvg55112, CSCvg55128, CSCvg55145, CSCvg58619, CSCvg64453, CSCvg64456, CSCvg64464, CSCvg64475, CSCvg68797.
Published 2017-11-16 · Modified
10.0EPSS 0.064
CVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
Published 2024-01-26 · Modified
10.0EPSS 0.024
CVE-2026-20045
Cisco Unified Communications Products Remote Code Execution Vulnerability
Published 2026-01-21 · Analyzed
9.8KEVEPSS 0.045
CVE-2022-20859
Cisco Unified Communications Products Access Control Vulnerability
Published 2022-07-06 · Modified
9.0EPSS 0.013
CVE-2021-1363
Cisco Unified Communications Manager IM & Presence Service SQL Injection Vulnerabilities
Published 2021-05-06 · Modified
8.1EPSS 0.011
CVE-2021-1365
Cisco Unified Communications Manager IM & Presence Service SQL Injection Vulnerabilities
Published 2021-05-06 · Modified
8.1EPSS 0.011
CVE-2022-20786
Cisco Unified Communications Manager IM & Presence Service SQL Injection Vulnerability
Published 2022-04-21 · Modified
8.1EPSS 0.008
CVE-2022-20791
Cisco Unified Communications Products Arbitrary File Read Vulnerability
Published 2022-07-06 · Modified
6.5EPSS 0.015
CVE-2021-1357
Cisco Unified Communications Products Vulnerabilities
Published 2021-01-20 · Modified
6.5EPSS 0.014
CVE-2021-1355
Cisco Unified Communications Products Vulnerabilities
Published 2021-01-20 · Modified
6.5EPSS 0.014
CVE-2021-1364
Cisco Unified Communications Products Vulnerabilities
Published 2021-01-20 · Modified
6.5EPSS 0.013
CVE-2021-1282
Cisco Unified Communications Products Vulnerabilities
Published 2021-01-20 · Modified
6.5EPSS 0.013
CVE-2020-3282
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2020-07-02 · Modified
6.1EPSS 0.008
CVE-2022-20800
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2022-07-06 · Modified
6.1EPSS 0.008
CVE-2022-20815
Cisco Unified Communications Products Cross-Site Scripting Vulnerability
Published 2022-07-06 · Modified
6.1EPSS 0.008
CVE-2025-20330
Cisco Unified Communications Manager IM and Presence Cross-Site Scripting Vulnerability
Published 2025-09-03 · Analyzed
6.1EPSS 0.003
CVE-2021-34701
Cisco Unified Communications Products Path Traversal Vulnerability
Published 2021-11-04 · Modified
4.3EPSS 0.016