VendorsCiscounified_contact_center_expressall versions
Vulnerabilities

Cisco Unified Contact Center Express

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2020-3280
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Published 2020-05-22 · Modified
10.0EPSS 0.069
CVE-2017-12337
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platform could allow an unauthenticated, remote attacker to gain unauthorized, elevated access to an affected device. The vulnerability occurs when a refresh upgrade (RU) or Prime Collaboration Deployment (PCD) migration is performed on an affected device. When a refresh upgrade or PCD migration is completed successfully, an engineering flag remains enabled and could allow root access to the device with a known password. If the vulnerable device is subsequently upgraded using the standard upgrade method to an Engineering Special Release, service update, or a new major release of the affected product, this vulnerability is remediated by that action. Note: Engineering Special Releases that are installed as COP files, as opposed to the standard upgrade method, do not remediate this vulnerability. An attacker who can access an affected device over SFTP while it is in a vulnerable state could gain root access to the device. This access could allow the attacker to compromise the affected system completely. Cisco Bug IDs: CSCvg22923, CSCvg55112, CSCvg55128, CSCvg55145, CSCvg58619, CSCvg64453, CSCvg64456, CSCvg64464, CSCvg64475, CSCvg68797.
Published 2017-11-16 · Modified
10.0EPSS 0.064
CVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by sending a crafted message to a listening port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of the web services user. With access to the underlying operating system, the attacker could also establish root access on the affected device.
Published 2024-01-26 · Modified
10.0EPSS 0.024
CVE-2018-0403
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to retrieve a cleartext password. Cisco Bug IDs: CSCvg71040.
Published 2018-07-18 · Modified
9.8EPSS 0.026
CVE-2025-20358
Cisco Unified Contact Center Express Editor Authentication Bypass Vulnerability
Published 2025-11-05 · Analyzed
9.8EPSS 0.009
CVE-2025-20354
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Published 2025-11-05 · Analyzed
9.8EPSS 0.009
CVE-2022-20658
Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
Published 2022-01-14 · Modified
9.6EPSS 0.014
CVE-2019-1888
Cisco Unified Contact Center Express Privilege Escalation Vulnerability
Published 2020-09-23 · Modified
9.0EPSS 0.034
CVE-2018-0402
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack. Cisco Bug IDs: CSCvg70921.
Published 2018-07-18 · Modified
8.8EPSS 0.010
CVE-2016-6427
Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
Published 2016-10-06 · Modified
8.8EPSS 0.006
CVE-2025-20274
Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
Published 2025-07-16 · Analyzed
8.8EPSS 0.004
CVE-2010-1571
Directory traversal vulnerability in the bootstrap service in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), unspecified 6.0 versions, and 5.0 before 5.0(2)SR3 allows remote attackers to read arbitrary files via a crafted bootstrap message to TCP port 6295.
Published 2010-06-10 · Modified
7.8EPSS 0.029
CVE-2010-1570
The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.
Published 2010-06-10 · Modified
7.8EPSS 0.025
CVE-2017-6779
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maximum size restriction. Therefore, the file is allowed to consume the majority of available disk space on the appliance. An attacker could exploit this vulnerability by sending crafted remote connection requests to the appliance. Successful exploitation could allow the attacker to increase the size of a system log file so that it consumes most of the disk space. The lack of available disk space could lead to a DoS condition in which the application functions could operate abnormally, making the appliance unstable. This vulnerability affects the following Cisco Voice Operating System (VOS)-based products: Emergency Responder, Finesse, Hosted Collaboration Mediation Fulfillment, MediaSense, Prime License Manager, SocialMiner, Unified Communications Manager (UCM), Unified Communications Manager IM and Presence Service (IM&P - earlier releases were known as Cisco Unified Presence), Unified Communication Manager Session Management Edition (SME), Unified Contact Center Express (UCCx), Unified Intelligence Center (UIC), Unity Connection, Virtualized Voice Browser. This vulnerability also affects Prime Collaboration Assurance and Prime Collaboration Provisioning. Cisco Bug IDs: CSCvd10872, CSCvf64322, CSCvf64332, CSCvi29538, CSCvi29543, CSCvi29544, CSCvi29546, CSCvi29556, CSCvi29571, CSCvi31738, CSCvi31741, CSCvi31762, CSCvi31807, CSCvi31818, CSCvi31823.
Published 2018-06-07 · Modified
7.8EPSS 0.020
CVE-2025-20275
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability
Published 2025-06-04 · Analyzed
7.8EPSS 0.002
CVE-2020-3177
Cisco Unified Communications Manager Path Traversal Vulnerability
Published 2020-04-15 · Modified
7.5EPSS 0.028
CVE-2019-12633
Cisco Unified Contact Center Express Request Processing Server-Side Request Forgery Vulnerability
Published 2019-09-05 · Modified
7.5EPSS 0.015
CVE-2016-6426
The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
Published 2016-10-05 · Modified
7.5EPSS 0.013
CVE-2025-20276
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Published 2025-06-04 · Analyzed
7.2EPSS 0.004
CVE-2025-20376
Cisco Unified Contact Center Express Remote Code Execution Vulnerability
Published 2025-11-05 · Analyzed
7.2EPSS 0.004
CVE-2025-20375
Cisco Unified Contact Center Express Arbitrary File Upload Vulnerability
Published 2025-11-05 · Analyzed
7.2EPSS 0.004
CVE-2020-3267
Cisco Unified Contact Center Express Improper API Authorization Vulnerability
Published 2020-06-03 · Modified
7.1EPSS 0.008
CVE-2025-20113
Cisco Unified Intelligence Center Privilege Escalation Vulnerability
Published 2025-05-21 · Analyzed
7.1EPSS 0.004
CVE-2025-20278
Cisco Unified Communications Products Command Injection Vulnerability
Published 2025-06-04 · Analyzed
6.7EPSS 0.002
CVE-2025-20277
Cisco Unified Contact Center Express Path Traversal Vulnerability
Published 2025-06-04 · Analyzed
6.7EPSS 0.002
CVE-2023-20061
Cisco Unified Intelligence Center Vulnerabilities
Published 2023-03-03 · Modified
6.5EPSS 0.007
CVE-2023-20062
Cisco Unified Intelligence Center Vulnerabilities
Published 2023-03-03 · Modified
6.5EPSS 0.005
CVE-2018-0400
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
Published 2018-07-18 · Modified
6.1EPSS 0.013
CVE-2018-0401
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
Published 2018-07-18 · Modified
6.1EPSS 0.012
CVE-2017-6722
A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.10000.61).
Published 2017-07-04 · Modified
6.1EPSS 0.012
CVE-2016-1298
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.
Published 2016-01-26 · Modified
6.1EPSS 0.011
CVE-2019-15259
Cisco Unified Contact Center Express HTTP Response Splitting Vulnerability
Published 2019-10-02 · Modified
6.1EPSS 0.011
CVE-2016-6425
Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
Published 2016-10-06 · Modified
6.1EPSS 0.010
CVE-2019-15278
Cisco Finesse Cross-Site Scripting Vulnerability
Published 2020-01-26 · Modified
6.1EPSS 0.009
CVE-2021-1463
Cisco Unified Intelligence Center Reflected Cross-Site Scripting Vulnerability
Published 2021-04-08 · Modified
6.1EPSS 0.008
CVE-2021-1395
Cisco Unified Intelligence Center Reflected Cross-Site Scripting Vulnerability
Published 2021-06-16 · Modified
6.1EPSS 0.008
CVE-2023-20058
A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.
Published 2023-01-19 · Modified
6.1EPSS 0.005
CVE-2026-20117
Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities
Published 2026-03-11 · Analyzed
6.1EPSS 0.002
CVE-2025-20288
Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability
Published 2025-07-16 · Analyzed
5.8EPSS 0.003
1 / 2Next →