VendorsCiscounity_serverall versions
Vulnerabilities

Cisco Unity Server

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2004-1322
Cisco Unity 2.x, 3.x, and 4.x, when integrated with Microsoft Exchange, has several hard coded usernames and passwords, which allows remote attackers to gain unauthorized access and change configuration settings or read outgoing or incoming e-mail messages.
Published 2005-01-06 · Modified
7.5EPSS 0.025
CVE-2002-1190
Cisco Unity 2.x and 3.x uses well-known default user accounts, which could allow remote attackers to gain access and place arbitrary calls.
Published 2002-10-15 · Modified
7.5EPSS 0.016
CVE-2005-0356
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
Published 2005-05-31 · Modified
5.01 PoCEPSS 0.828
CVE-2002-1189
The default configuration of Cisco Unity 2.x and 3.x does not block international operator calls in the predefined restriction tables, which could allow authenticated users to place international calls using call forwarding.
Published 2004-09-01 · Modified
4.6EPSS 0.004