cbcvebase.

Cisco Unified Communications Manager vulnerabilities

52 known vulnerabilities affecting cisco/cisco_unified_communications_manager.

Total CVEs
52
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL3HIGH15MEDIUM34

Vulnerabilities

Page 3 of 3
CVE-2023-20242P4MEDIUMCVSS 6.1v12.0(1)SU1v12.0(1)SU2+17 more2023-08-16
CVE-2023-20242 [MEDIUM] CWE-79 CVE-2023-20242: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains
nvd
CVE-2024-20511P4MEDIUMCVSS 6.1v12.5(1)SU2v12.0(1)SU2+24 more2024-11-06
CVE-2024-20511 [MEDIUM] CWE-79 CVE-2024-20511: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists becau
nvd
CVE-2022-20804P4MEDIUMCVSS 6.5vn/a2022-04-21
CVE-2022-20804 [MEDIUM] CWE-754 CVE-2022-20804: A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. This vulnerability
nvd
CVE-2019-12715P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12715 [MEDIUM] CWE-79 CVE-2019-12715: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insu
nvd
CVE-2019-12716P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12716 [MEDIUM] CWE-79 CVE-2019-12716: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of us
nvd
CVE-2020-3346P4MEDIUMCVSS 6.1vn/a2020-08-17
CVE-2020-3346 [MEDIUM] CWE-79 CVE-2020-3346: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web UI does not prope
nvd
CVE-2023-20116P4MEDIUMCVSS 5.7v12.0(1)SU1v12.0(1)SU2+15 more2023-06-28
CVE-2023-20116 [MEDIUM] CWE-835 CVE-2023-20116: A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Mana A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insuff
nvd
CVE-2020-3420P4MEDIUMCVSS 5.4vN/A2024-11-18
CVE-2020-3420 [MEDIUM] CWE-79 CVE-2020-3420: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability is due to insuffic
nvd
CVE-2021-1406P4MEDIUMCVSS 4.9vn/a2021-04-08
CVE-2021-1406 [MEDIUM] CWE-538 CVE-2021-1406: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper inclusion of sensitive information in downloadable files. An
nvd
CVE-2025-20112P4MEDIUMCVSS 5.1v12.5(1)SU2v12.5(1)SU1+19 more2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing craf
nvd
CVE-2021-1399P4MEDIUMCVSS 4.3vn/a2021-04-08
CVE-2021-1399 [MEDIUM] CWE-302 CVE-2021-1399: A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cis A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system without proper authorization. The vulnerability is due to insufficient validation of user-su
nvd
CVE-2025-20361P4MEDIUMCVSS 4.8v12.5(1)SU2v12.5(1)SU1+20 more2025-10-01
CVE-2025-20361 [MEDIUM] CWE-79 CVE-2025-20361: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase