Cisco Unified Contact Center Express vulnerabilities

38 known vulnerabilities affecting cisco/cisco_unified_contact_center_express.

Total CVEs
38
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH9MEDIUM25

Vulnerabilities

Page 2 of 2
CVE-2024-20405MEDIUMCVSS 6.1vN/A2024-06-05
CVE-2024-20405 [MEDIUM] CWE-20 CVE-2024-20405: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct a stored XSS attack by exploiting an RFI vulnerability. This vulnerability is due to insufficient validation of user-supplied input for specific HTTP requests that are sent to an affected device. An attacker could exploit
cvelistv5nvd
CVE-2024-20253CRITICALCVSS 10.0v8.5(1)v9.0(2)SU3ES04+56 more2024-01-26
CVE-2024-20253 [CRITICAL] CWE-502 CVE-2024-20253: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by se
cvelistv5nvd
CVE-2023-20232MEDIUMCVSS 5.3v8.5(1)v9.0(2)SU3ES04+53 more2023-08-16
CVE-2023-20232 [MEDIUM] CWE-20 CVE-2023-20232: A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP re
cvelistv5nvd
CVE-2023-20096MEDIUMCVSS 5.4vn/a2023-04-05
CVE-2023-20096 [MEDIUM] CWE-79 CVE-2023-20096: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by entering craf
cvelistv5nvd
CVE-2023-20058MEDIUMCVSS 6.1v11.0(1)SU1v12.0(1)+5 more2023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
cvelistv5nvd
CVE-2021-1395MEDIUMCVSS 6.1vn/a2021-06-16
CVE-2021-1395 [MEDIUM] CWE-79 CVE-2021-1395: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could
cvelistv5nvd
CVE-2021-1254MEDIUMCVSS 4.8vn/a2021-05-22
CVE-2021-1254 [MEDIUM] CWE-79 CVE-2021-1254: Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authe Multiple vulnerabilities in the web-based management interface of Cisco Finesse could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of the affected software. An a
cvelistv5nvd
CVE-2021-1358MEDIUMCVSS 6.1vn/a2021-05-22
CVE-2021-1358 [MEDIUM] CWE-601 CVE-2021-1358: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to redirect a user to an undesired web page. This vulnerability is due to improper input validation of the URL parameters in an HTTP request that is sent to an affected system. An attacker could exploit this vulnerability by persuadin
cvelistv5nvd
CVE-2021-1463MEDIUMCVSS 6.1vn/a2021-04-08
CVE-2021-1463 [MEDIUM] CWE-79 CVE-2021-1463: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacke
cvelistv5nvd
CVE-2019-1888HIGHCVSS 7.2vn/a2020-09-23
CVE-2019-1888 [HIGH] CWE-434 CVE-2019-1888: A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified A vulnerability in the Administration Web Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to upload arbitrary files and execute commands on the underlying operating system. To exploit this vulnerability, an attacker needs valid Administrator credentials. The vulnerability is due to insufficie
cvelistv5nvd
CVE-2020-3267HIGHCVSS 7.1vn/a2020-06-03
CVE-2020-3267 [HIGH] CWE-285 CVE-2020-3267: A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could all A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected sys
cvelistv5nvd
CVE-2020-3280CRITICALCVSS 9.8vn/a2020-05-22
CVE-2020-3280 [CRITICAL] CWE-20 CVE-2020-3280: A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Uni A vulnerability in the Java Remote Management Interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. An attacker could exploit this vulnerabil
cvelistv5nvd
CVE-2019-15259MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-15259 [MEDIUM] CWE-113 CVE-2019-15259: A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticat A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by co
cvelistv5nvd
CVE-2019-12633HIGHCVSS 7.5≥ unspecified, < 12.0(1)SU0.12019-09-05
CVE-2019-12633 [HIGH] CWE-20 CVE-2019-12633: A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated A vulnerability in Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to bypass access controls and conduct a server-side request forgery (SSRF) attack on a targeted system. The vulnerability is due to improper validation of user-supplied input on the affected system. An attacker could exploit this vulner
cvelistv5nvd
CVE-2019-12626MEDIUMCVSS 4.8≥ unspecified, < 12.0(1)ES022019-08-21
CVE-2019-12626 [MEDIUM] CWE-20 CVE-2019-12626: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied
cvelistv5nvd
CVE-2019-1670MEDIUMCVSS 6.1vn/a2019-02-07
CVE-2019-1670 [MEDIUM] CWE-79 CVE-2019-1670: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could
cvelistv5nvd
CVE-2017-12288MEDIUMCVSS 6.1vCisco Unified Contact Center Express2017-10-19
CVE-2017-12288 [MEDIUM] CWE-79 CVE-2017-12288: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attacker to condu A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to insufficient validation of user-supplied input
cvelistv5
CVE-2017-6722MEDIUMCVSS 6.1vCisco Unified Contact Center Express2017-07-04
CVE-2017-6722 [MEDIUM] CVE-2017-6722: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthe A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Release
cvelistv5