Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 11 of 11
CVE-2015-4272P4MEDIUMCVSS 4.3v10.5\(2.10000.5\)2015-07-14
CVE-2015-4272 [MEDIUM] CWE-79 CVE-2015-4272: Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communicatio
Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManager) 10.5(2.10000.5) allow remote attackers to inject arbitrary web script or HTML via a crafted parameter, aka Bug ID CSCut19580.
nvd
CVE-2014-3315P4MEDIUMCVSS 4.3v10.0\(1\)_base2014-07-10
CVE-2014-3315 [MEDIUM] CWE-79 CVE-2014-3315: Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA)
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCup76308.
nvd
CVE-2013-6978P4MEDIUMCVSS 4.0≤ 9.1\(1\)v3.3\(5\)+111 more2013-12-21
CVE-2013-6978 [MEDIUM] CWE-200 CVE-2013-6978: The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) an
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249.
nvd
CVE-2015-4269P4MEDIUMCVSS 4.0v10.5\(1.99995.9\)2015-07-14
CVE-2015-4269 [MEDIUM] CWE-399 CVE-2015-4269: The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote
The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a denial of service (management outage) by sending many requests, aka Bug ID CSCuu99709.
nvd
CVE-2009-0057P4MEDIUMCVSS 4.3v5.0v5.0_1+24 more2009-01-22
CVE-2009-0057 [MEDIUM] CWE-20 CVE-2009-0057: The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before 6.1(3) allows remote attackers to cause a denial of service (voice service outage) by sending malformed input over a TCP session in which the "client terminates prematurely."
nvd
CVE-2007-4633P4MEDIUMCVSS 4.3v4.2.3sr2v4.2.3sr2b2007-08-31
CVE-2007-4633 [MEDIUM] CWE-79 CVE-2007-4633: Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 before 4.1(3)sr5, 4.2 before 4.2(3)sr2, and 4.3 before 4.3(1)sr1 allow remote attackers to inject arbitrary web script or HTML via the lang variable to the (1) user or (2) admin logon page, aka CSCsi10728.
nvd
CVE-2014-3363P4LOWCVSS 3.5v9.1\(2.10000.28\)2014-09-12
CVE-2014-3363 [LOW] CWE-79 CVE-2014-3363: Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manage
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.28) allows remote authenticated users to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuq68443.
nvd
CVE-2013-4869P4UNKNOWNCVSS 0.0≥ 7.1\(1\), ≤ 9.1\(2\)2013-07-18
CVE-2013-4869 [NONE] CWE-522 CVE-2013-4869: Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in C
Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' installations, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge
nvd
← Previous11 / 11