cbcvebase.

Cisco Emergency Responder vulnerabilities

9 known vulnerabilities affecting cisco/cisco_emergency_responder.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2023-20101P2CRITICALCVSS 9.8v12.5(1)SU42023-10-04
CVE-2023-20101 [CRITICAL] CWE-798 CVE-2023-20101: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use du
nvd
CVE-2024-20352P2HIGHCVSS 8.8v10.5(1a)v10.5(1)+33 more2024-04-03
CVE-2024-20352 [HIGH] CWE-23 CVE-2024-20352: A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduc A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by
nvd
CVE-2023-20266P3HIGHCVSS 7.2v12.5(1)SU4v12.5(1)SU8a+1 more2023-08-30
CVE-2023-20266 [HIGH] CWE-347 CVE-2023-20266: A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cis A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability exists because the applicatio
nvd
CVE-2023-20259P3HIGHCVSS 7.5v12.5(1)SU7v14+1 more2023-10-04
CVE-2023-20259 [HIGH] CWE-400 CVE-2023-20259: A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is unlikely to be used in normal operati
nvd
CVE-2021-1226P3MEDIUMCVSS 6.5vn/a2021-01-13
CVE-2021-1226 [MEDIUM] CWE-532 CVE-2021-1226: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unifie A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sen
nvd
CVE-2024-20347P3MEDIUMCVSS 6.5vN/A2024-04-03
CVE-2024-20347 [MEDIUM] CWE-352 CVE-2024-20347: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to cond A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2018-15403P4MEDIUMCVSS 5.4vn/a2018-10-05
CVE-2018-15403 [MEDIUM] CWE-601 CVE-2018-15403: A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Mana A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the paramete
nvd
CVE-2025-20112P4MEDIUMCVSS 5.1v12.5(1a)v12.5(1)SU1+20 more2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing craf
nvd
CVE-2019-16025P4MEDIUMCVSS 4.8vn/a2020-09-23
CVE-2019-16025 [MEDIUM] CWE-79 CVE-2019-16025: A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remo A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of some parameters that are passed to the web server of the affected software. An attac
nvd
Cisco Emergency Responder vulnerabilities | cvebase