Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 4 of 11
CVE-2009-2051P3HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+1 more2009-08-27
CVE-2009-2051 [HIGH] CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message t
nvd
CVE-2025-20278P3MEDIUMCVSS 6.7v12.5\(1\)v12.5\(1\)su1+10 more2025-06-04
CVE-2025-20278 [MEDIUM] CWE-77 CVE-2025-20278: A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenti
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user.
This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerab
nvd
CVE-2011-1605P3HIGHCVSS 7.8v6.0v6.1\(1\)+44 more2011-05-03
CVE-2011-1605 [HIGH] CVE-2011-1605: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCth39586.
nvd
CVE-2011-1606P3HIGHCVSS 7.8v6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1606 [HIGH] CVE-2011-1606: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtg62855.
nvd
CVE-2015-0751P3HIGHCVSS 7.8v10.3\(1\)2015-05-29
CVE-2015-0751 [HIGH] CWE-20 CVE-2015-0751: Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a denial of service via crafted packets, aka Bug ID CSCus81800.
nvd
CVE-2010-2835P3HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+35 more2010-09-23
CVE-2010-2835 [HIGH] CVE-2010-2835: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allow remote attackers to cause a denial of service (device reload or voice-services ou
nvd
CVE-2011-2564P3HIGHCVSS 7.8v8.0v8.0\(1\)+7 more2011-08-29
CVE-2011-2564 [HIGH] CVE-2011-2564: Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communicatio
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth19417.
nvd
CVE-2011-2563P3HIGHCVSS 7.8v8.0v8.0\(1\)+7 more2011-08-29
CVE-2011-2563 [HIGH] CVE-2011-2563: Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communicatio
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth26669.
nvd
CVE-2011-4486P3HIGHCVSS 7.8v6.0v6.0\(1\)+68 more2012-03-01
CVE-2011-4486 [HIGH] CWE-399 CVE-2011-4486: Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before
Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration,
nvd
CVE-2014-0731P3MEDIUMCVSS 5.0≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-22
CVE-2014-0731 [MEDIUM] CWE-264 CVE-2014-0731: The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlie
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and read Java class files via a direct request, aka Bug ID CSCum46497.
nvd
CVE-2007-4294P3MEDIUMCVSS 6.8v5.0v5.1+1 more2007-08-09
CVE-2007-4294 [MEDIUM] CVE-2007-4294: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remote attackers to execute arbitrary code via a malformed SIP packet, aka CSCsi80102.
nvd
CVE-2013-3412P3MEDIUMCVSS 6.5v7.1\(2a\)v7.1\(2a\)su1+54 more2013-07-18
CVE-2013-3412 [MEDIUM] CWE-89 CVE-2013-3412: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) all
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCuh81766.
nvd
CVE-2019-15963P3MEDIUMCVSS 6.5≥ 10.5, ≤ 10.5\(2.10000.5\)≥ 11.5, ≤ 11.5\(1.10000.6\)+2 more2020-09-23
CVE-2019-15963 [MEDIUM] CWE-200 CVE-2019-15963: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive information in the web-based management interface of the affected software. The vulnerability is due to insufficient protection of user-supplied input by the web-based management interface of th
nvd
CVE-2009-2050P3HIGHCVSS 7.8fixed in 6.1\(1\)2009-08-27
CVE-2009-2050 [HIGH] CVE-2009-2050: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote at
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
nvd
CVE-2009-2053P3HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+2 more2009-08-27
CVE-2009-2053 [HIGH] CVE-2009-2053: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236.
nvd
CVE-2009-2054P3HIGHCVSS 7.8≥ 4.0, < 5.1\(3g\)≥ 6.0, < 6.1\(4\)+2 more2009-08-27
CVE-2009-2054 [HIGH] CWE-770 CVE-2009-2054: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
nvd
CVE-2010-0592P3HIGHCVSS 7.8v4.1v4.1\(3\)+46 more2010-03-05
CVE-2010-0592 [HIGH] CVE-2010-0592: The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x
The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.
nvd
CVE-2010-0587P3HIGHCVSS 7.8v4.1v4.1\(3\)+48 more2010-03-05
CVE-2010-0587 [HIGH] CVE-2010-0587: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x befo
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.
nvd
CVE-2008-2061P3HIGHCVSS 7.8≥ 5.0, < 5.1\(3c\)≥ 6.0, < 6.1\(2\)2008-06-26
CVE-2008-2061 [HIGH] CWE-20 CVE-2008-2061: The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CU
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x before 6.1(2) allows remote attackers to cause a denial of service (TSP crash) via malformed network traffic to TCP port 2748.
nvd
CVE-2013-3453P3HIGHCVSS 7.8≤ 8.6\(4\)v3.3\(5\)+112 more2013-08-22
CVE-2013-3453 [HIGH] CWE-399 CVE-2013-3453: Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x
Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID CSCud84959.
nvd