VendorsCiscounified_intelligence_center11.5\(1\)
Vulnerabilities

Cisco Unified 11.5\(1\)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2017-12253
A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs: CSCve76872.
Published 2017-09-21 · Modified
8.8EPSS 0.012
CVE-2025-20274
Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability
Published 2025-07-16 · Analyzed
8.8EPSS 0.004
CVE-2025-20113
Cisco Unified Intelligence Center Privilege Escalation Vulnerability
Published 2025-05-21 · Analyzed
7.1EPSS 0.004
CVE-2017-12254
A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by convincing the user to access a malicious link or by intercepting the user request and injecting the malicious code. An exploit could allow the attacker to execute arbitrary code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76848, CSCve76856.
Published 2017-09-21 · Modified
6.1EPSS 0.023
CVE-2017-12248
A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected software. An attacker could exploit this vulnerability by persuading a user to click a malicious link or by intercepting a user request and injecting malicious code into the request. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected site or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCve76835.
Published 2017-09-21 · Modified
6.1EPSS 0.017
CVE-2025-20288
Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability
Published 2025-07-16 · Analyzed
5.8EPSS 0.003
CVE-2025-20114
Cisco Unified Intelligence Center Insecure Direct Object Reference Vulnerability
Published 2025-05-21 · Analyzed
4.3EPSS 0.003