Cisco Unified Communications Manager vulnerabilities

207 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
207
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1

Vulnerabilities

Page 4 of 11
CVE-2018-0411MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-08-01
CVE-2018-0411 [MEDIUM] CWE-79 CVE-2018-0411: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by th
nvd
CVE-2017-6779HIGHCVSS 7.5≥ 10.0, < 10.5\(2\)su5≥ 11.0, < 11.0\(1a\)su4+5 more2018-06-07
CVE-2017-6779 [HIGH] CWE-399 CVE-2017-6779: Multiple Cisco products are affected by a vulnerability in local file management for certain system Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maxi
nvd
CVE-2018-0355MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-06-07
CVE-2018-0355 [MEDIUM] CWE-20 CVE-2018-0355: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an un A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affected system. The vulnerability is due to insufficient protections for HTML inline frames (iframes) by the web UI of the affected softw
nvd
CVE-2018-0340MEDIUMCVSS 5.4v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-06-07
CVE-2018-0340 [MEDIUM] CWE-79 CVE-2018-0340: A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) softwa A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of certain parameters passed to the we
nvd
CVE-2018-0328MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-05-17
CVE-2018-0328 [MEDIUM] CWE-79 CVE-2018-0328: A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Prese A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed
nvd
CVE-2018-0266MEDIUMCVSS 4.3v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-04-19
CVE-2018-0266 [MEDIUM] CWE-200 CVE-2018-0266: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker
nvd
CVE-2018-0267MEDIUMCVSS 6.5v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-04-19
CVE-2018-0267 [MEDIUM] CWE-200 CVE-2018-0267: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by b
nvd
CVE-2018-0206MEDIUMCVSS 6.1v11.5\(1.13900.52\)2018-02-22
CVE-2018-0206 [MEDIUM] CWE-79 CVE-2018-0206: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by th
nvd
CVE-2018-0135MEDIUMCVSS 4.3v11.0\(1.24075.1\)2018-02-08
CVE-2018-0135 [MEDIUM] CWE-20 CVE-2018-0135: A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacke A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search input. An attacker could exploit this vulnerability by sending malicious requests to an affected sys
nvd
CVE-2018-0120MEDIUMCVSS 4.3v11.5\(1.13900.52\)2018-02-08
CVE-2018-0120 [MEDIUM] CWE-89 CVE-2018-0120: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerability exists because the affected software fails to validate user-supplied input in certain SQL queries that bypass protection filters. An attacker could ex
nvd
CVE-2017-12357MEDIUMCVSS 5.4v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2017-11-30
CVE-2017-12357 [MEDIUM] CWE-79 CVE-2017-12357: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2017-6791HIGHCVSS 7.5v9.1\(2.10000.28\)v10.0\(1.10000.24\)+2 more2017-09-07
CVE-2017-6791 [HIGH] CWE-119 CVE-2017-6791: A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager coul A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper handling of Transport Layer Security (TLS) traffic by the affected software. An attacker could exploit thi
nvd
CVE-2017-6785MEDIUMCVSS 4.3v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-08-17
CVE-2017-6785 [MEDIUM] CWE-20 CVE-2017-6785: A vulnerability in configuration modification permissions validation for Cisco Unified Communication A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker to perform a horizontal privilege escalation where one user can modify another user's configuration. The vulnerability is due to lack of proper Role Based Access Control (RBAC) when certain user con
nvd
CVE-2017-6757HIGHCVSS 8.8v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-08-07
CVE-2017-6757 [HIGH] CWE-89 CVE-2017-6757: A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5( A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-supplied input used in SQL queries that bypass protection filters. An attacker could exploit this vulne
nvd
CVE-2017-6758MEDIUMCVSS 6.5v11.5\(1.10000.6\)2017-08-07
CVE-2017-6758 [MEDIUM] CWE-22 CVE-2017-6758: A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could a A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote attacker to access arbitrary files in the context of the web root directory structure on an affected device. The vulnerability is due to insufficient input validation by the affected software. An attacker could exploit this
nvd
CVE-2017-6654MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-05-22
CVE-2017-6654 [MEDIUM] CWE-79 CVE-2017-6654: A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 t A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 through 11.5 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied in
nvd
CVE-2017-3808HIGHCVSS 7.5v10.0\(1.10000.12\)v10.0_base+18 more2017-04-20
CVE-2017-3808 [HIGH] CWE-119 CVE-2017-3808: A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Com A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Unified CM) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate limiting protection. An attacker could exploit this vu
nvd
CVE-2017-3886MEDIUMCVSS 4.9v11.0\(1.10000.10\)v11.5\(1.10000.6\)2017-04-07
CVE-2017-3886 [MEDIUM] CWE-89 CVE-2017-3886: A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticat A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affec
nvd
CVE-2017-3888MEDIUMCVSS 5.4v12.0\(0.98000.452\)2017-04-07
CVE-2017-3888 [MEDIUM] CWE-79 CVE-2017-3888: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability affects Cisco Unified Communications Manager with a default con
nvd
CVE-2017-3872MEDIUMCVSS 6.1v10.5\(2.10000.5\)v10.5\(2.14076.1\)+2 more2017-03-17
CVE-2017-3872 [MEDIUM] CWE-79 CVE-2017-3872: A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Ci A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of an affected device. More Information: CSCvc21620. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.641
nvd