cbcvebase.

Cisco Unified Communications Manager vulnerabilities

208 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1

Vulnerabilities

Page 3 of 11
CVE-2022-20790P3MEDIUMCVSS 6.5≤ 14.02022-04-21
CVE-2022-20790 [MEDIUM] CWE-23 CVE-2022-20790: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files from the underlying operating system. This vulnerability exists because the web-based mana
nvd
CVE-2014-0734P3HIGHCVSS 7.5≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-20
CVE-2014-0734 [HIGH] CWE-89 CVE-2014-0734: SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cis SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCum46483.
nvd
CVE-2013-3404P3HIGHCVSS 7.5v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3404 [HIGH] CWE-89 CVE-2013-3404: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) al SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, leading to discovery of encrypted credentials by leveraging metadata, aka Bug ID CSCuh01051.
nvd
CVE-2024-20375P3HIGHCVSS 7.5v12.0\(1\)su1v12.0\(1\)su2+14 more2024-08-21
CVE-2024-20375 [HIGH] CWE-787 CVE-2024-20375: A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper parsing o
nvd
CVE-2022-20791P3MEDIUMCVSS 6.5≤ 11.5\(1.10000.6\)≥ 12.5, ≤ 12.5\(1.10000.22\)+1 more2022-07-06
CVE-2022-20791 [MEDIUM] CWE-36 CVE-2022-20791: A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM) A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to read arbitrary files on the underlying
nvd
CVE-2017-3808P3HIGHCVSS 7.5v10.0\(1.10000.12\)v10.0_base+18 more2017-04-20
CVE-2017-3808 [HIGH] CWE-119 CVE-2017-3808: A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Com A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate limiting protection. An attacker could exploit this vu
nvd
CVE-2017-6791P3HIGHCVSS 7.5v9.1\(2.10000.28\)v10.0\(1.10000.24\)+2 more2017-09-07
CVE-2017-6791 [HIGH] CWE-119 CVE-2017-6791: A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager coul A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of Transport Layer Security (TLS) traffic by the affected software. An attacker could exploit thi
nvd
CVE-2019-1887P3HIGHCVSS 7.5v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-07-06
CVE-2019-1887 [HIGH] CWE-787 CVE-2019-1887: A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Co A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of input SIP traffic. An attacker could exploit this vulnerability by sending a malforme
nvd
CVE-2021-1355P3MEDIUMCVSS 6.5fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1355 [MEDIUM] CWE-35 CVE-2021-1355: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1357P3MEDIUMCVSS 6.5fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1357 [MEDIUM] CWE-35 CVE-2021-1357: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2017-6779P3HIGHCVSS 7.5≥ 10.0, < 10.5\(2\)su5≥ 11.0, < 11.0\(1a\)su4+5 more2018-06-07
CVE-2017-6779 [HIGH] CWE-399 CVE-2017-6779: Multiple Cisco products are affected by a vulnerability in local file management for certain system Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maxi
nvd
CVE-2011-4487P3MEDIUMCVSS 6.8v6.0v6.0\(1\)+68 more2012-03-01
CVE-2011-4487 [MEDIUM] CWE-89 CVE-2011-4487: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a craf
nvd
CVE-2022-20789P3MEDIUMCVSS 6.5v12.5\(1\)v14.02022-04-21
CVE-2022-20789 [MEDIUM] CWE-73 CVE-2022-20789: A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to write arbitrary files on the affected system. This vulnerability is due to improper restrictions applied to a system
nvd
CVE-2015-6433P3MEDIUMCVSS 6.5v11.0\(0.98000.225\)2016-01-08
CVE-2015-6433 [MEDIUM] CWE-89 CVE-2015-6433: SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCut66767.
nvd
CVE-2013-3402P3MEDIUMCVSS 6.5v7.1\(2a\)v7.1\(2a\)su1+54 more2013-07-18
CVE-2013-3402 [MEDIUM] CWE-94 CVE-2013-3402: An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, aka Bug ID CSCuh73440.
nvd
CVE-2009-2052P3HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+2 more2009-08-27
CVE-2009-2052 [HIGH] CVE-2009-2052: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "trackin
nvd
CVE-2019-15272P3MEDIUMCVSS 6.5v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-15272 [MEDIUM] CWE-264 CVE-2019-15272: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to bypass security restrictions. The vulnerability is due to improper handling of malformed HTTP methods. An attacker could exploit this vulnerabi
nvd
CVE-2012-3949P3HIGHCVSS 7.8v6.0\(1a\)v6.0\(1b\)+37 more2012-09-27
CVE-2012-3949 [HIGH] CWE-20 CVE-2012-3949: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a cra
nvd
CVE-2013-6688P3MEDIUMCVSS 6.3≤ 9.1\(1\)v3.3\(5\)+111 more2013-11-18
CVE-2013-6688 [MEDIUM] CWE-22 CVE-2013-6688: Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.
nvd
CVE-2021-1226P3MEDIUMCVSS 6.5≥ 11.5\(1\), < 11.5\(1\)su9v10.5\(2\)2021-01-13
CVE-2021-1226 [MEDIUM] CWE-532 CVE-2021-1226: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unifie A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sen
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase