cbcvebase.

Cisco Unity Connection vulnerabilities

31 known vulnerabilities affecting cisco/cisco_unity_connection.

Total CVEs
31
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH5MEDIUM23

Vulnerabilities

Page 2 of 2
CVE-2021-1380P4MEDIUMCVSS 6.1vn/a2021-04-08
CVE-2021-1380 [MEDIUM] CWE-89 CVE-2021-1380: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1408P4MEDIUMCVSS 6.1vn/a2021-04-08
CVE-2021-1408 [MEDIUM] CWE-89 CVE-2021-1408: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2022-20800P4MEDIUMCVSS 6.1vn/a2022-07-06
CVE-2022-20800 [MEDIUM] CWE-79 CVE-2022-20800: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc
nvd
CVE-2019-12707P4MEDIUMCVSS 6.1≥ unspecified, < n/a2019-10-02
CVE-2019-12707 [MEDIUM] CWE-79 CVE-2019-12707: A vulnerability in the web-based interface of multiple Cisco Unified Communications products could a A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based inte
nvd
CVE-2020-3282P4MEDIUMCVSS 6.1vn/a2020-07-02
CVE-2020-3282 [MEDIUM] CWE-79 CVE-2020-3282: A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us
nvd
CVE-2025-20112P4MEDIUMCVSS 5.1v12.5(1)v12.5(1)SU1+17 more2025-05-21
CVE-2025-20112 [MEDIUM] CWE-268 CVE-2025-20112: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to excessive permissions that have been assigned to system commands. An attacker could exploit this vulnerability by executing craf
nvd
CVE-2021-34701P4MEDIUMCVSS 4.3vn/a2021-11-04
CVE-2021-34701 [MEDIUM] CWE-22 CVE-2021-34701: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access s
nvd
CVE-2026-20060P4MEDIUMCVSS 4.7v14v14SU1+8 more2026-04-15
CVE-2026-20060 [MEDIUM] CWE-601 CVE-2026-20060: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unaut A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A su
nvd
CVE-2020-3129P4MEDIUMCVSS 4.8≥ unspecified, < n/a2020-01-26
CVE-2020-3129 [MEDIUM] CWE-79 CVE-2020-3129: A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted d
nvd
CVE-2018-15426P4MEDIUMCVSS 4.8vn/a2018-10-05
CVE-2018-15426 [MEDIUM] CWE-79 CVE-2018-15426: A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, r A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based inter
nvd
CVE-2024-20305P4MEDIUMCVSS 4.8v12.0(1)SU1v12.0(1)SU2+18 more2024-01-26
CVE-2024-20305 [MEDIUM] CWE-79 CVE-2024-20305: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authe A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit thi
nvd
Cisco Unity Connection vulnerabilities | cvebase