cbcvebase.

Cisco Unified Communications Domain Manager vulnerabilities

30 known vulnerabilities affecting cisco/unified_communications_domain_manager.

Total CVEs
30
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM24UNKNOWN5

Vulnerabilities

Page 2 of 2
CVE-2014-3277MEDIUMCVSS 4.0≤ 9.0\(.1\)v7.4+3 more2014-05-29
CVE-2014-3277 [MEDIUM] CWE-287 CVE-2014-3277: The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager ( The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive user and group information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum77005
nvd
CVE-2014-3279MEDIUMCVSS 5.0≤ 9.0\(.1\)v7.4+3 more2014-05-29
CVE-2014-3279 [MEDIUM] CWE-264 CVE-2014-3279: The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager ( The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote attackers to enumerate account names via a crafted URL, aka Bug IDs CSCun39631 and CSCun39643.
nvd
CVE-2014-3283MEDIUMCVSS 5.8≤ 9.0\(.1\)v7.4+3 more2014-05-29
CVE-2014-3283 [MEDIUM] CWE-20 CVE-2014-3283: Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Open redirect vulnerability in Self-Care Client Portal applications in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCun79731.
nvd
CVE-2014-3282MEDIUMCVSS 4.0≤ 9.0\(.1\)v7.4+3 more2014-05-29
CVE-2014-3282 [MEDIUM] CWE-264 CVE-2014-3282: The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager ( The Administration GUI in the web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain sensitive number-translation information by leveraging Location Administrator privileges and entering a crafted URL, aka Bug ID CSCum7
nvd
CVE-2014-2104MEDIUMCVSS 4.3v9.0\(.1\)2014-03-02
CVE-2014-2104 [MEDIUM] CWE-79 CVE-2014-2104: Multiple cross-site scripting (XSS) vulnerabilities in the Business Voice Services Manager (BVSM) pa Multiple cross-site scripting (XSS) vulnerabilities in the Business Voice Services Manager (BVSM) page in Cisco Unified Communications Domain Manager 9.0(.1) allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCum78536, CSCum78526, CSCum69809, and CSCum63113.
nvd
CVE-2014-2198UNKNOWN
CVE-2014-2198 Multiple Vulnerabilities in Cisco Unified Communications Domain Manager CVE-2014-2198: Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Cisco Unified Communications Domain Manager (Cisco Unified CDM) is affected by the following vulnerabilities: Cisco Unified Communications Domain Manager Privilege Escalation Vulnerability Cisco Unified Communications Domain Manager Default SSH Key Vulnerability Cisco Unified Communications Domain Manager BVSMWeb Unauthorized
cisco
CVE-2016-1314UNKNOWN
CVE-2016-1314 Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability CVE-2016-1314: Cisco Unified Communications Domain Manager Cross-Site Scripting Vulnerability A vulnerability in the Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to execute a cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation of user-supplied input. An attacker could exploit this vulnerability by convinci
cisco
CVE-2014-2197UNKNOWN
CVE-2014-2197 Multiple Vulnerabilities in Cisco Unified Communications Domain Manager CVE-2014-2197: Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Cisco Unified Communications Domain Manager (Cisco Unified CDM) is affected by the following vulnerabilities: Cisco Unified Communications Domain Manager Privilege Escalation Vulnerability Cisco Unified Communications Domain Manager Default SSH Key Vulnerability Cisco Unified Communications Domain Manager BVSMWeb Unauthorized
cisco
CVE-2014-3300UNKNOWNPoC
CVE-2014-3300 Multiple Vulnerabilities in Cisco Unified Communications Domain Manager CVE-2014-3300: Multiple Vulnerabilities in Cisco Unified Communications Domain Manager Cisco Unified Communications Domain Manager (Cisco Unified CDM) is affected by the following vulnerabilities: Cisco Unified Communications Domain Manager Privilege Escalation Vulnerability Cisco Unified Communications Domain Manager Default SSH Key Vulnerability Cisco Unified Communications Domain Manager BVSMWeb Unauthorized
cisco
CVE-2018-0364UNKNOWNCVSS 3.0
CVE-2018-0364 Cisco Unified Communications Domain Manager Cross-Site Request Forgery Vulnerability CVE-2018-0364: Cisco Unified Communications Domain Manager Cross-Site Request Forgery Vulnerability A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF
cisco