Cisco Emergency Responder vulnerabilities

12 known vulnerabilities affecting cisco/cisco_emergency_responder.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2025-20112MEDIUMCVSS 5.1v12.5(1a)v12.5(1)SU1+20 more2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing craf
cvelistv5nvd
CVE-2024-20352HIGHCVSS 8.8v10.5(1a)v10.5(1)+33 more2024-04-03
CVE-2024-20352 [HIGH] CWE-23 CVE-2024-20352: A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduc A vulnerability in Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a directory traversal attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by
cvelistv5nvd
CVE-2024-20347MEDIUMCVSS 6.5vN/A2024-04-03
CVE-2024-20347 [MEDIUM] CWE-352 CVE-2024-20347: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to cond A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a CSRF attack, which could allow the attacker to perform arbitrary actions on an affected device. This vulnerability is due to insufficient protections for the web UI of an affected system. An attacker could exploit this vulnerability by persuadin
cvelistv5nvd
CVE-2023-20101CRITICALCVSS 9.8v12.5(1)SU42023-10-04
CVE-2023-20101 [CRITICAL] CWE-798 CVE-2023-20101: A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log A vulnerability in Cisco Emergency Responder could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are typically reserved for use du
cvelistv5nvd
CVE-2023-20259HIGHCVSS 7.5v12.5(1)SU7v14+1 more2023-10-04
CVE-2023-20259 [HIGH] CWE-400 CVE-2023-20259: A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attacker to cause high CPU utilization, which could impact access to the web-based management interface and cause delays with call processing. This API is not used for device management and is unlikely to be used in normal operati
cvelistv5nvd
CVE-2023-20266HIGHCVSS 7.2v12.5(1)SU4v12.5(1)SU8a+1 more2023-08-30
CVE-2023-20266 [HIGH] CWE-347 CVE-2023-20266: A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cis A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an authenticated, remote attacker to elevate privileges to root on an affected device. This vulnerability exists because the applicatio
cvelistv5nvd
CVE-2021-1226MEDIUMCVSS 6.5vn/a2021-01-13
CVE-2021-1226 [MEDIUM] CWE-532 CVE-2021-1226: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unifie A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sen
cvelistv5nvd
CVE-2019-16025MEDIUMCVSS 4.8vn/a2020-09-23
CVE-2019-16025 [MEDIUM] CWE-79 CVE-2019-16025: A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remo A vulnerability in the web framework of Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The vulnerability is due to insufficient validation of some parameters that are passed to the web server of the affected software. An attac
cvelistv5nvd
CVE-2018-15403MEDIUMCVSS 5.4vn/a2018-10-05
CVE-2018-15403 [MEDIUM] CWE-601 CVE-2018-15403: A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Mana A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the paramete
cvelistv5nvd
CVE-2017-12227MEDIUMCVSS 5.4vCisco Emergency Responder2017-09-07
CVE-2017-12227 [MEDIUM] CWE-89 CVE-2017-12227: A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injec A vulnerability in the SQL database interface for Cisco Emergency Responder could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could
cvelistv5
CVE-2016-6468HIGHCVSS 8.8vCisco Emergency Responder2016-12-14
CVE-2016-6468 [HIGH] CVE-2016-6468: A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross- A vulnerability in the web-based management interface of Cisco Emergency Responder could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. More Information: CSCvb06663. Known Affected Releases: 11.5(1.10000.4). Kno
cvelistv5
CVE-2016-9208MEDIUMCVSS 6.5vCisco Emergency Responder2016-12-14
CVE-2016-9208 [MEDIUM] CVE-2016-9208: A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an A vulnerability in the File Management Utility, the Download File form, and the Serviceability application of Cisco Emergency Responder could allow an authenticated, remote attacker to access files in arbitrary locations on the file system of an affected device. More Information: CSCva98951 CSCva98954 CSCvb574
cvelistv5