VendorsCiscounified_customer_voice_portalany version
Vulnerabilities

Cisco Unified Customer Voice Portal (CVP) Software any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
Published 2021-12-10 · Analyzed
10.0KEV3 PoCEPSS 1.000
CVE-2013-1221
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to execute arbitrary code via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38384.
Published 2013-05-09 · Modified
10.0EPSS 0.034
CVE-2018-0086
A vulnerability in the application server of the Cisco Unified Customer Voice Portal (CVP) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device. The vulnerability is due to malformed SIP INVITE traffic received on the CVP during communications with the Cisco Virtualized Voice Browser (VVB). An attacker could exploit this vulnerability by sending malformed SIP INVITE traffic to the targeted appliance. An exploit could allow the attacker to impact the availability of services and data on the device, causing a DoS condition. This vulnerability affects Cisco Unified CVP running any software release prior to 11.6(1). Cisco Bug IDs: CSCve85840.
Published 2018-01-18 · Modified
8.6EPSS 0.023
CVE-2013-1224
Directory traversal vulnerability in the Resource Manager in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to overwrite arbitrary files via a crafted (1) HTTP or (2) HTTPS request that triggers incorrect parameter validation, aka Bug ID CSCub38369.
Published 2013-05-09 · Modified
7.8EPSS 0.021
CVE-2013-1225
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.
Published 2013-05-09 · Modified
7.8EPSS 0.016
CVE-2013-1223
The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372.
Published 2013-05-09 · Modified
7.8EPSS 0.015
CVE-2013-1220
The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.
Published 2013-05-09 · Modified
7.8EPSS 0.013
CVE-2013-1222
The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.
Published 2013-05-09 · Modified
7.8EPSS 0.012
CVE-2020-3402
Cisco Unified Customer Voice Portal Information Disclosure Vulnerability
Published 2020-07-02 · Modified
7.5EPSS 0.016
CVE-2019-16017
Cisco Unified Customer Voice Portal Insecure Direct Object Reference Vulnerability
Published 2020-09-23 · Modified
6.8EPSS 0.009
CVE-2021-1599
Cisco Unified Customer Voice Portal Cross-Site Scripting Vulnerability
Published 2021-07-22 · Modified
5.4EPSS 0.008
CVE-2014-3325
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Customer Voice Portal (CVP) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug IDs CSCuh61711, CSCuh61720, CSCuh61723, CSCuh61726, CSCuh61727, CSCuh61731, and CSCuh61733.
Published 2014-07-19 · Modified
4.3EPSS 0.014