Cisco Unified Communications Manager vulnerabilities
207 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
207
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1
Vulnerabilities
Page 2 of 11
CVE-2022-20862MEDIUMCVSS 4.3fixed in 12.5\(1\)su6≥ 14.0, < 14su22022-07-06
CVE-2022-20862 [MEDIUM] CWE-23 CVE-2022-20862: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to imp
nvd
CVE-2022-20804MEDIUMCVSS 6.5≤ 14.02022-04-21
CVE-2022-20804 [MEDIUM] CWE-754 CVE-2022-20804: A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. This vulnerability
nvd
CVE-2022-20787MEDIUMCVSS 6.8≥ 12.5\(1\), < 12.5\(1\)su6≥ 14.0, < 14su12022-04-21
CVE-2022-20787 [MEDIUM] CWE-352 CVE-2022-20787: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF pr
nvd
CVE-2022-20790MEDIUMCVSS 6.5≤ 14.02022-04-21
CVE-2022-20790 [MEDIUM] CWE-23 CVE-2022-20790: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based mana
nvd
CVE-2022-20789MEDIUMCVSS 6.5v12.5\(1\)v14.02022-04-21
CVE-2022-20789 [MEDIUM] CWE-73 CVE-2022-20789: A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system. This vulnerability is due to improper restrictions applied to a system
nvd
CVE-2022-20788MEDIUMCVSS 6.1≥ 11.5\(1\), < 11.5\(1\)su11≥ 12.5\(1\), < 12.5\(1\)su6+1 more2022-04-21
CVE-2022-20788 [MEDIUM] CWE-79 CVE-2022-20788: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists b
nvd
CVE-2021-44228CRITICALCVSS 10.0KEVPoCfixed in 11.5\(1\)v11.5\(1\)+6 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2021-34701MEDIUMCVSS 4.3fixed in 14su12021-11-04
CVE-2021-34701 [MEDIUM] CWE-22 CVE-2021-34701: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access s
nvd
CVE-2021-34773MEDIUMCVSS 6.5v14.0\(1.10000.20\)2021-11-04
CVE-2021-34773 [MEDIUM] CWE-352 CVE-2021-34773: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request
nvd
CVE-2021-1478MEDIUMCVSS 6.5fixed in 12.62021-05-06
CVE-2021-1478 [MEDIUM] CWE-284 CVE-2021-1478: A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Ma
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an uns
nvd
CVE-2021-1362HIGHCVSS 8.8≥ 10.5\(2\), < 11.5\(1\)su9≥ 12.0\(1\), < 12.5\(1\)su42021-04-08
CVE-2021-1362 [HIGH] CWE-94 CVE-2021-1362: A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Comm
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and Cisco Prime License Manager could allow an authenticated, remote attacker to execute arbitrary code on an affected device
nvd
CVE-2021-1407MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1407 [MEDIUM] CWE-89 CVE-2021-1407: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1409MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1409 [MEDIUM] CWE-89 CVE-2021-1409: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1380MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1380 [MEDIUM] CWE-89 CVE-2021-1380: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1406MEDIUMCVSS 4.9v10.5\(2\)v10.5\(2\)su1+29 more2021-04-08
CVE-2021-1406 [MEDIUM] CWE-538 CVE-2021-1406: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper inclusion of sensitive information in downloadable files. An
nvd
CVE-2021-1408MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1408 [MEDIUM] CWE-89 CVE-2021-1408: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1399MEDIUMCVSS 4.3≥ 10.5\(2\), < 12.5\(1\)su42021-04-08
CVE-2021-1399 [MEDIUM] CWE-302 CVE-2021-1399: A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cis
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to modify data on an affected system without proper authorization. The vulnerability is due to insufficient validation of user-su
nvd
CVE-2021-1282MEDIUMCVSS 4.9fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1282 [MEDIUM] CWE-35 CVE-2021-1282: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1355MEDIUMCVSS 6.5fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1355 [MEDIUM] CWE-35 CVE-2021-1355: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1357MEDIUMCVSS 6.5fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1357 [MEDIUM] CWE-35 CVE-2021-1357: Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd