Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 10 of 11
CVE-2014-0657P4MEDIUMCVSS 4.0≤ 9.1\(1\)v3.3\(5\)+111 more2014-01-08
CVE-2014-0657 [MEDIUM] CWE-264 CVE-2014-0657: The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier do
The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role restrictions, which allows remote authenticated users to bypass role-based access control via multiple visits to a forbidden portal URL, aka Bug ID CSCuj83540.
nvd
CVE-2015-0717P4MEDIUMCVSS 6.9v10.0\(1.10000.12\)2015-05-16
CVE-2015-0717 [MEDIUM] CWE-20 CVE-2015-0717: Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a co
Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified parameter, aka Bug ID CSCut19546.
nvd
CVE-2021-1399P4MEDIUMCVSS 4.3≥ 10.5\(2\), < 12.5\(1\)su42021-04-08
CVE-2021-1399 [MEDIUM] CWE-302 CVE-2021-1399: A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cis
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system without proper authorization. The vulnerability is due to insufficient validation of user-su
nvd
CVE-2014-0741P4MEDIUMCVSS 6.2≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-27
CVE-2014-0741 [MEDIUM] CWE-310 CVE-2014-0741: The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation
The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to read or modify arbitrary files via a crafted command, aka Bug ID CSCum95461.
nvd
CVE-2015-6425P4MEDIUMCVSS 5.0v10.5\(0.98000.88\)2015-12-16
CVE-2015-6425 [MEDIUM] CWE-399 CVE-2015-6425: The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.980
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers to cause a denial of service (subsystem outage) via invalid session tokens, aka Bug ID CSCul83786.
nvd
CVE-2018-0135P4MEDIUMCVSS 4.3v11.0\(1.24075.1\)2018-02-08
CVE-2018-0135 [MEDIUM] CWE-20 CVE-2018-0135: A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacke
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search input. An attacker could exploit this vulnerability by sending malicious requests to an affected sys
nvd
CVE-2014-0742P4MEDIUMCVSS 6.2≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-27
CVE-2014-0742 [MEDIUM] CWE-20 CVE-2014-0742: The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in
The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to read or modify arbitrary files via unspecified vectors, aka Bug ID CSCum95464.
nvd
CVE-2014-0735P4MEDIUMCVSS 4.3≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-20
CVE-2014-0735 [MEDIUM] CWE-79 CVE-2014-0735: Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unifi
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCum46470.
nvd
CVE-2014-3332P4MEDIUMCVSS 4.0≤ 8.6\(2\)2014-08-11
CVE-2014-3332 [MEDIUM] CVE-2014-3332: Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions sett
Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authenticated users to establish undetected concurrent logins via unspecified vectors, aka Bug ID CSCup98029.
nvd
CVE-2015-4295P4MEDIUMCVSS 4.0v10.5\(3.10000.9\)2015-08-01
CVE-2015-4295 [MEDIUM] CWE-200 CVE-2015-4295: The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9)
The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated users to discover root credentials via a direct request to an unspecified URL, aka Bug ID CSCuv21819.
nvd
CVE-2014-0686P4MEDIUMCVSS 6.0≤ 9.1\(2.10000.28\)v9.1\(1\)+1 more2014-02-04
CVE-2014-0686 [MEDIUM] CWE-264 CVE-2014-0686: Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local user
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by leveraging incorrect file permissions, aka Bug IDs CSCul24917 and CSCul24908.
nvd
CVE-2011-4019P4MEDIUMCVSS 5.4v7.0v7.0\(1\)+31 more2012-05-03
CVE-2011-4019 [MEDIUM] CWE-399 CVE-2011-4019: Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM)
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.
nvd
CVE-2012-0376P4MEDIUMCVSS 5.0v8.52012-05-03
CVE-2012-0376 [MEDIUM] CVE-2012-0376: The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attack
The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367.
nvd
CVE-2014-7991P4MEDIUMCVSS 4.3≤ 10.0\(1\)v10.02014-11-14
CVE-2014-7991 [MEDIUM] CWE-310 CVE-2014-7991: The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the Subject Alternative Name (SAN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof VCS core devices via a crafted certificate issued by a legitimate Certification Authority, aka Bug ID CSCuq8637
nvd
CVE-2014-0747P4MEDIUMCVSS 6.8≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-27
CVE-2014-0747 [MEDIUM] CWE-20 CVE-2014-0747: The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications M
The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows local users to inject commands via unspecified CAPF programs, aka Bug ID CSCum95493.
nvd
CVE-2014-3316P4MEDIUMCVSS 4.0v10.0\(1\)_base2014-07-10
CVE-2014-3316 [MEDIUM] CWE-20 CVE-2014-3316: The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to bypass intended upload restrictions via a crafted parameter, aka Bug ID CSCup76297.
nvd
CVE-2013-3433P4MEDIUMCVSS 6.8v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3433 [MEDIUM] CVE-2013-3433: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02276.
nvd
CVE-2013-3434P4MEDIUMCVSS 6.8v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3434 [MEDIUM] CVE-2013-3434: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.
nvd
CVE-2013-3403P4MEDIUMCVSS 6.8v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3403 [MEDIUM] CVE-2013-3403: Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x)
Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454.
nvd
CVE-2007-3776P4MEDIUMCVSS 5.0v5.0v5.1\(1\)+1 more2007-07-15
CVE-2007-3776 [MEDIUM] CVE-2007-3776: Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS)
Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obtain sensitive information via unspecified vectors that reveal the SNMP community strings and configuration settings, aka (1) CSCsj20668 and (2) CSCsj25962.
nvd