cbcvebase.

Cisco Unified Communications Manager vulnerabilities

52 known vulnerabilities affecting cisco/cisco_unified_communications_manager.

Total CVEs
52
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH15MEDIUM34

Vulnerabilities

Page 2 of 3
CVE-2021-1355P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1355 [MEDIUM] CWE-35 CVE-2021-1355: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1357P3MEDIUMCVSS 6.5vn/a2021-01-20
CVE-2021-1357 [MEDIUM] CWE-35 CVE-2021-1357: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2022-20789P3MEDIUMCVSS 6.5vn/a2022-04-21
CVE-2022-20789 [MEDIUM] CWE-73 CVE-2022-20789: A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system. This vulnerability is due to improper restrictions applied to a system
nvd
CVE-2019-15272P3MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-02
CVE-2019-15272 [MEDIUM] CWE-264 CVE-2019-15272: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper handling of malformed HTTP methods. An attacker could exploit this vulnerabi
nvd
CVE-2025-20278P3MEDIUMCVSS 6.7v12.5(1)SU2v12.5(1)SU1+19 more2025-06-04
CVE-2025-20278 [MEDIUM] CWE-77 CVE-2025-20278: A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenti A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerab
nvd
CVE-2021-34773P3MEDIUMCVSS 6.5vn/a2021-11-04
CVE-2021-34773 [MEDIUM] CWE-352 CVE-2021-34773: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request
nvd
CVE-2022-20787P4MEDIUMCVSS 6.8vn/a2022-04-21
CVE-2022-20787 [MEDIUM] CWE-352 CVE-2022-20787: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF pr
nvd
CVE-2019-12711P4MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-02
CVE-2019-12711 [MEDIUM] CWE-611 CVE-2019-12711: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. A
nvd
CVE-2021-1478P4MEDIUMCVSS 6.5vn/a2021-05-06
CVE-2021-1478 [MEDIUM] CWE-284 CVE-2021-1478: A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Ma A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an uns
nvd
CVE-2019-1915P4MEDIUMCVSS 6.5≥ unspecified, < n/a2019-10-02
CVE-2019-1915 [MEDIUM] CWE-352 CVE-2019-1915: A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Co A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS
nvd
CVE-2019-12710P4MEDIUMCVSS 4.9≥ unspecified, < n/a2019-10-02
CVE-2019-12710 [MEDIUM] CWE-89 CVE-2019-12710: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by executing arbitrary SQL queries. The vulnerability exists because the affected software improp
nvd
CVE-2022-20752P4MEDIUMCVSS 5.3vn/a2022-07-06
CVE-2022-20752 [MEDIUM] CWE-208 CVE-2022-20752: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exp
nvd
CVE-2021-1282P4MEDIUMCVSS 4.9vn/a2021-01-20
CVE-2021-1282 [MEDIUM] CWE-35 CVE-2021-1282: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1364P4MEDIUMCVSS 4.9vn/a2021-01-20
CVE-2021-1364 [MEDIUM] CWE-35 CVE-2021-1364: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2015-0749P4MEDIUMCVSS 6.1≥ next of 11.5(0.98000.108), < unspecified2020-02-19
CVE-2015-0749 [MEDIUM] CWE-79 CVE-2015-0749: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attac A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user
nvd
CVE-2020-3532P4MEDIUMCVSS 6.1vN/A2024-11-18
CVE-2020-3532 [MEDIUM] CWE-79 CVE-2020-3532: A vulnerability in the web-based management interface of Cisco&nbsp;Unified Communications Manager, A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a use
nvd
CVE-2024-20488P4MEDIUMCVSS 6.1v12.5(1)SU2v12.0(1)SU2+22 more2024-08-21
CVE-2024-20488 [MEDIUM] CWE-79 CVE-2024-20488: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists becau
nvd
CVE-2022-20862P4MEDIUMCVSS 4.3vn/a2022-07-06
CVE-2022-20862 [MEDIUM] CWE-23 CVE-2022-20862: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to imp
nvd
CVE-2022-20788P4MEDIUMCVSS 6.1vn/a2022-04-21
CVE-2022-20788 [MEDIUM] CWE-79 CVE-2022-20788: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists b
nvd
CVE-2022-20815P4MEDIUMCVSS 6.1vn/a2022-07-06
CVE-2022-20815 [MEDIUM] CWE-79 CVE-2022-20815: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase