Cisco Unified Communications Manager vulnerabilities
51 known vulnerabilities affecting cisco/cisco_unified_communications_manager.
Total CVEs
51
CISA KEV
1
actively exploited
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH14MEDIUM34
Vulnerabilities
Page 2 of 3
CVE-2022-20752MEDIUMCVSS 5.3vn/a2022-07-06
CVE-2022-20752 [MEDIUM] CWE-208 CVE-2022-20752: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exp
cvelistv5nvd
CVE-2022-20815MEDIUMCVSS 6.1vn/a2022-07-06
CVE-2022-20815 [MEDIUM] CWE-79 CVE-2022-20815: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains
cvelistv5nvd
CVE-2022-20862MEDIUMCVSS 4.3vn/a2022-07-06
CVE-2022-20862 [MEDIUM] CWE-23 CVE-2022-20862: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to imp
cvelistv5nvd
CVE-2022-20791MEDIUMCVSS 6.5vn/a2022-07-06
CVE-2022-20791 [MEDIUM] CWE-36 CVE-2022-20791: A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to read arbitrary files on the underlying
cvelistv5nvd
CVE-2022-20804MEDIUMCVSS 6.5vn/a2022-04-21
CVE-2022-20804 [MEDIUM] CWE-754 CVE-2022-20804: A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. This vulnerability
cvelistv5nvd
CVE-2022-20787MEDIUMCVSS 6.8vn/a2022-04-21
CVE-2022-20787 [MEDIUM] CWE-352 CVE-2022-20787: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF pr
cvelistv5nvd
CVE-2022-20788MEDIUMCVSS 6.1vn/a2022-04-21
CVE-2022-20788 [MEDIUM] CWE-79 CVE-2022-20788: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists b
cvelistv5nvd
CVE-2022-20790MEDIUMCVSS 6.5vn/a2022-04-21
CVE-2022-20790 [MEDIUM] CWE-23 CVE-2022-20790: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based mana
cvelistv5nvd
CVE-2022-20789MEDIUMCVSS 6.5vn/a2022-04-21
CVE-2022-20789 [MEDIUM] CWE-73 CVE-2022-20789: A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system. This vulnerability is due to improper restrictions applied to a system
cvelistv5nvd
CVE-2021-34773MEDIUMCVSS 6.5vn/a2021-11-04
CVE-2021-34773 [MEDIUM] CWE-352 CVE-2021-34773: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request
cvelistv5nvd
CVE-2021-1478MEDIUMCVSS 6.5vn/a2021-05-06
CVE-2021-1478 [MEDIUM] CWE-284 CVE-2021-1478: A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Ma
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an uns
cvelistv5nvd
CVE-2021-1406MEDIUMCVSS 4.9vn/a2021-04-08
CVE-2021-1406 [MEDIUM] CWE-538 CVE-2021-1406: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper inclusion of sensitive information in downloadable files. An
cvelistv5nvd
CVE-2021-1399MEDIUMCVSS 4.3vn/a2021-04-08
CVE-2021-1399 [MEDIUM] CWE-302 CVE-2021-1399: A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cis
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system without proper authorization. The vulnerability is due to insufficient validation of user-su
cvelistv5nvd
CVE-2021-1282MEDIUMCVSS 4.9vn/a2021-01-20
CVE-2021-1282 [MEDIUM] CWE-35 CVE-2021-1282: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
cvelistv5nvd
CVE-2021-1355MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1355 [MEDIUM] CWE-35 CVE-2021-1355: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
cvelistv5nvd
CVE-2021-1357MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1357 [MEDIUM] CWE-35 CVE-2021-1357: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
cvelistv5nvd
CVE-2021-1364MEDIUMCVSS 4.9vn/a2021-01-20
CVE-2021-1364 [MEDIUM] CWE-35 CVE-2021-1364: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
cvelistv5nvd
CVE-2020-3135HIGHCVSS 8.8vn/a2020-09-23
CVE-2020-3135 [HIGH] CWE-352 CVE-2020-3135: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM)
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. The vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected device. An attacker
cvelistv5nvd
CVE-2020-3346MEDIUMCVSS 6.1vn/a2020-08-17
CVE-2020-3346 [MEDIUM] CWE-79 CVE-2020-3346: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web UI does not prope
cvelistv5nvd
CVE-2020-3177HIGHCVSS 7.5vn/a2020-04-15
CVE-2020-3177 [HIGH] CWE-22 CVE-2020-3177: A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communication
A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct directory traversal attacks on an affected device. The vulnerability is due to insufficient validation of u
cvelistv5nvd