cbcvebase.

Cisco Unified Communications Manager vulnerabilities

208 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1

Vulnerabilities

Page 5 of 11
CVE-2010-2834P3HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+38 more2010-09-23
CVE-2010-2834 [HIGH] CVE-2010-2834: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)SU1, 7.x before 7.1(5), and 8.0 before 8.0(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via crafted SIP registration traffic ov
nvd
CVE-2011-2560P3HIGHCVSS 7.8v4.1\(3\)v4.1\(3\)sr1+12 more2011-08-29
CVE-2011-2560 [HIGH] CWE-399 CVE-2011-2560: The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory consumption and restart) by making many connections, aka Bug ID CSCtf97162.
nvd
CVE-2011-1607P3MEDIUMCVSS 6.5v6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1607 [MEDIUM] CWE-22 CVE-2011-1607: Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallMa Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.
nvd
CVE-2021-34773P3MEDIUMCVSS 6.5v14.0\(1.10000.20\)2021-11-04
CVE-2021-34773 [MEDIUM] CWE-352 CVE-2021-34773: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site request
nvd
CVE-2009-2864P4HIGHCVSS 7.8v5.1\(1b\)v5.1\(1c\)+17 more2009-09-28
CVE-2009-2864 [HIGH] CVE-2009-2864: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
nvd
CVE-2008-1746P4HIGHCVSS 7.8v4.1v4.2+4 more2008-05-16
CVE-2008-1746 [HIGH] CWE-20 CVE-2008-1746: The SNMP Trap Agent service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR6, 4.2 The SNMP Trap Agent service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (core dump and service restart) via a series of malformed UDP packets, as demonstrated by the IP Stack Integrity Checker (IS
nvd
CVE-2011-2072P4HIGHCVSS 7.8v6.0v6.1\(1\)+55 more2011-10-03
CVE-2011-2072 [HIGH] CWE-399 CVE-2011-2072: Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified C Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su4, 8.x before 8.5(1)su2, and 8.6 before 8.6(1) allows remote attackers to cause a denial of service (memory consumption and device reload or process failure) via a malformed SIP message, aka Bug IDs
nvd
CVE-2010-0591P4HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0591 [HIGH] CVE-2010-0591: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
nvd
CVE-2013-3459P4HIGHCVSS 7.8v7.1\(2a\)v7.1\(2a\)su1+21 more2013-08-25
CVE-2013-3459 [HIGH] CWE-399 CVE-2013-3459: Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a denial of service (service disruption) via malformed registration messages, aka Bug ID CSCuf93466.
nvd
CVE-2014-0733P3MEDIUMCVSS 5.0≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-20
CVE-2014-0733 [MEDIUM] CWE-287 CVE-2014-0733: The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read ELM files via a direct request to a URL, aka Bug ID CSCum46494.
nvd
CVE-2017-3886P3MEDIUMCVSS 4.9v11.0\(1.10000.10\)v11.5\(1.10000.6\)2017-04-07
CVE-2017-3886 [MEDIUM] CWE-89 CVE-2017-3886: A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticat A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL Injection. The attacker must be authenticated as an administrative user to execute SQL database queries. More Information: CSCvc74291. Known Affec
nvd
CVE-2022-20787P4MEDIUMCVSS 6.8≥ 12.5\(1\), < 12.5\(1\)su6≥ 14.0, < 14su12022-04-21
CVE-2022-20787 [MEDIUM] CWE-352 CVE-2022-20787: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unified CM Session Management Edition (SME) Software could allow an authenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected device. This vulnerability is due to insufficient CSRF pr
nvd
CVE-2019-12711P4MEDIUMCVSS 6.5v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-12711 [MEDIUM] CWE-611 CVE-2019-12711: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition. The vulnerability is due to improper restrictions on XML entities. A
nvd
CVE-2021-1478P4MEDIUMCVSS 6.5fixed in 12.62021-05-06
CVE-2021-1478 [MEDIUM] CWE-284 CVE-2021-1478: A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Ma A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an uns
nvd
CVE-2019-1915P4MEDIUMCVSS 6.5v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-1915 [MEDIUM] CWE-352 CVE-2019-1915: A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Co A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS
nvd
CVE-2010-0590P4HIGHCVSS 7.8v7.0v7.0\(1\)+3 more2010-03-05
CVE-2010-0590 [HIGH] CVE-2010-0590: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
nvd
CVE-2013-3460P4HIGHCVSS 7.8v8.6v8.6\(1\)+13 more2013-08-25
CVE-2013-3460 [HIGH] CWE-399 CVE-2013-3460: Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) bef Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a high rate of UDP packets, aka Bug ID CSCub85597.
nvd
CVE-2013-1133P4HIGHCVSS 7.8v8.6v8.6\(1\)+6 more2013-02-27
CVE-2013-1133 [HIGH] CWE-20 CVE-2013-1133: Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to cause a denial of service (CPU consumption and GUI and voice outages) via malformed packets to unused UDP ports, aka Bug ID CSCtx43337.
nvd
CVE-2010-2838P4HIGHCVSS 7.8≤ 7.0\(2a\)su2v7.0\(1\)su1+23 more2010-08-26
CVE-2010-2838 [HIGH] CVE-2010-2838: The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerl The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305.
nvd
CVE-2010-2837P4HIGHCVSS 7.8≤ 6.1\(5\)v6.1\(1\)+38 more2010-08-26
CVE-2010-2837 [HIGH] CVE-2010-2837: The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallMa The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310.
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase