Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 1 of 11
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 11.5\(1\)v11.5\(1\)+6 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2026-20230P1HIGHCVSS 8.6KEVPoC≥ 14.0, < 14su6≥ 15.0, ≤ 15su4a2026-06-03
CVE-2026-20230 [HIGH] CWE-918 CVE-2026-20230: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.
This vulnerability is due to improper input validation for specific
nvd
CVE-2026-20045P1CRITICALCVSS 9.8KEVPoC≥ 12.5, < 14su5≥ 15.0, ≤ 15su3a2026-01-21
CVE-2026-20045 [CRITICAL] CWE-94 CVE-2026-20045: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to ex
nvd
CVE-2011-3315P2HIGHCVSS 7.8ExploitedPoCv5.0v5.1+60 more2011-10-27
CVE-2011-3315 [HIGH] CWE-22 CVE-2011-3315: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)S
nvd
CVE-2011-1609P2HIGHCVSS 8.5PoCv6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1609 [HIGH] CWE-89 CVE-2011-1609: SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager)
SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.
nvd
CVE-2024-20253P1CRITICALCVSS 10.0fixed in 12.5\(1\)su8≥ 14.0, < 14su32024-01-26
CVE-2024-20253 [CRITICAL] CWE-502 CVE-2024-20253: A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-provided data that is being read into memory. An attacker could exploit this vulnerability by se
nvd
CVE-2025-20309P2CRITICALCVSS 10.0v15.0.1.13010-1v15.0.1.13011-1+6 more2025-07-02
CVE-2025-20309 [CRITICAL] CWE-798 CVE-2025-20309: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.
This vulnerabilit
nvd
CVE-2010-3039P3MEDIUMCVSS 6.8PoCv6.0v6.1\(1\)+41 more2010-11-09
CVE-2010-3039 [MEDIUM] CWE-78 CVE-2010-3039: /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly Cal
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.
nvd
CVE-2007-4634P3CRITICALCVSS 9.3PoCv3.3\(5\)v3.3\(5\)sr1+13 more2007-08-31
CVE-2007-4634 [CRITICAL] CWE-89 CVE-2007-4634: Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to execute arbitrary SQL commands via the lang variable to the (1) user or (2) admin logon page, aka CSCsi64265.
nvd
CVE-2008-0027P3CRITICALCVSS 10.0v4.2v4.2.3sr2+2 more2008-01-17
CVE-2008-0027 [CRITICAL] CWE-119 CVE-2008-0027: Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in
Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM) 4.2 before 4.2(3)SR3 and 4.3 before 4.3(1)SR1, and CallManager 4.0 and 4.1 before 4.1(3)SR5c, allows remote attackers to cause a denial of service or execute arbitrary code via a long request.
nvd
CVE-2021-1362P2HIGHCVSS 8.8≥ 10.5\(2\), < 11.5\(1\)su9≥ 12.0\(1\), < 12.5\(1\)su42021-04-08
CVE-2021-1362 [HIGH] CWE-94 CVE-2021-1362: A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Comm
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device
nvd
CVE-2008-1154P3CRITICALCVSS 10.0v5.0v5.1+2 more2008-04-04
CVE-2008-1154 [CRITICAL] CWE-287 CVE-2008-1154: The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, includ
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Manager (CUCM) 5.x and 6.x, Unified Presence 1.x and 6.x, Emergency Responder 2.x, and Mobility Manager 2.x, does not require authentication for requests received from the network, which allows remote attackers to execute ar
nvd
CVE-2023-20211P3HIGHCVSS 8.8≥ 12.5\(1\), < 12.5\(1\)subv14.02023-08-16
CVE-2023-20211 [HIGH] CWE-89 CVE-2023-20211: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability is due to improper validation of user-sup
nvd
CVE-2022-20859P3HIGHCVSS 8.8≥ 14.0, < 14su22022-07-06
CVE-2022-20859 [HIGH] CWE-284 CVE-2022-20859: A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to perform certain administrative actions they should not be able to. This vulnerability is due to
nvd
CVE-2023-20010P3HIGHCVSS 8.8fixed in 12.5\(1\)su7≥ 11.5\(1\), < 12.5\(1\)su7+1 more2023-01-20
CVE-2023-20010 [HIGH] CWE-89 CVE-2023-20010: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.
This vulnerability exists because the web-based management i
nvd
CVE-2019-15972P3HIGHCVSS 8.8v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-11-26
CVE-2019-15972 [HIGH] CWE-89 CVE-2019-15972: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web-based management interface improperly validates SQL values. An attacker could exploit this vulnerability by authentica
nvd
CVE-2008-0026P3MEDIUMCVSS 6.5PoCv5.0v5.0_1+9 more2008-02-14
CVE-2008-0026 [MEDIUM] CWE-89 CVE-2008-0026: SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 befor
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6.1(1a) allows remote authenticated users to execute arbitrary SQL commands via the key parameter to the (1) admin and (2) user interface pages.
nvd
CVE-2011-1610P3MEDIUMCVSS 6.4v6.0v6.1\(1\)+46 more2011-05-03
CVE-2011-1610 [MEDIUM] CWE-89 CVE-2011-1610: Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server co
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or
nvd
CVE-2017-6757P3HIGHCVSS 8.8v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-08-07
CVE-2017-6757 [HIGH] CWE-89 CVE-2017-6757: A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(
A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulne
nvd
CVE-2018-0474P3HIGHCVSS 8.8v10.5\(2.14076.1\)2019-01-10
CVE-2018-0474 [HIGH] CWE-200 CVE-2018-0474: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view digest credentials in clear text. The vulnerability is due to the incorrect inclusion of saved passwords in configuration pages. An attacker could exploit this vulnerability by logging in to the Cisco Unified
nvd
1 / 11Next →