cbcvebase.

Cisco Unified Contact Center Express vulnerabilities

36 known vulnerabilities affecting cisco/cisco_unified_contact_center_express.

Total CVEs
36
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH9MEDIUM23

Vulnerabilities

Page 2 of 2
CVE-2024-20405MEDIUMCVSS 6.1vN/A2024-06-05
CVE-2024-20405 [MEDIUM] CWE-20 CVE-2024-20405: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit
nvd
CVE-2024-20253CRITICALCVSS 10.0v8.5(1)v9.0(2)SU3ES04+56 more2024-01-26
CVE-2024-20253 [CRITICAL] CWE-502 CVE-2024-20253: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by se
nvd
CVE-2023-20232MEDIUMCVSS 5.3v8.5(1)v9.0(2)SU3ES04+53 more2023-08-16
CVE-2023-20232 [MEDIUM] CWE-20 CVE-2023-20232: A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP re
nvd
CVE-2023-20096MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20096 [MEDIUM] CWE-79 CVE-2023-20096: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by entering craf
nvd
CVE-2023-20058MEDIUMCVSS 6.1v11.0(1)SU1v12.0(1)+5 more2023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
nvd
CVE-2021-1395MEDIUMCVSS 6.1vn/a2021-06-16
CVE-2021-1395 [MEDIUM] CWE-79 CVE-2021-1395: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could
nvd
CVE-2021-1358MEDIUMCVSS 6.1vn/a2021-05-22
CVE-2021-1358 [MEDIUM] CWE-601 CVE-2021-1358: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuadin
nvd
CVE-2021-1254MEDIUMCVSS 4.8vn/a2021-05-22
CVE-2021-1254 [MEDIUM] CWE-79 CVE-2021-1254: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authe Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An a
nvd
CVE-2021-1463MEDIUMCVSS 6.1vn/a2021-04-08
CVE-2021-1463 [MEDIUM] CWE-79 CVE-2021-1463: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacke
nvd
CVE-2019-1888HIGHCVSS 7.2vn/a2020-09-23
CVE-2019-1888 [HIGH] CWE-434 CVE-2019-1888: A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials. The vulnerability is due to insufficie
nvd
CVE-2020-3267HIGHCVSS 7.1vn/a2020-06-03
CVE-2020-3267 [HIGH] CWE-285 CVE-2020-3267: A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could all A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected sys
nvd
CVE-2020-3280CRITICALCVSS 9.8vn/a2020-05-22
CVE-2020-3280 [CRITICAL] CWE-20 CVE-2020-3280: A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Uni A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerabil
nvd
CVE-2019-15259MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-15259 [MEDIUM] CWE-113 CVE-2019-15259: A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticat A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by co
nvd
CVE-2019-12633HIGHCVSS 7.5≥ unspecified, < 12.0(1)SU0.12019-09-05
CVE-2019-12633 [HIGH] CWE-20 CVE-2019-12633: A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An attacker could exploit this vulner
nvd
CVE-2019-12626MEDIUMCVSS 4.8≥ unspecified, < 12.0(1)ES022019-08-21
CVE-2019-12626 [MEDIUM] CWE-20 CVE-2019-12626: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied
nvd
CVE-2019-1670MEDIUMCVSS 6.1vn/a2019-02-07
CVE-2019-1670 [MEDIUM] CWE-79 CVE-2019-1670: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could
nvd
Cisco Unified Contact Center Express vulnerabilities | cvebase