cbcvebase.

Cisco Unified Communications Manager vulnerabilities

208 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1

Vulnerabilities

Page 6 of 11
CVE-2011-2562P4HIGHCVSS 7.8v6.0v6.1\(1\)+46 more2011-08-29
CVE-2011-2562 [HIGH] CVE-2011-2562: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6 Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (service outage) via a SIP INVITE message, aka Bug ID CSCth43256.
nvd
CVE-2014-3319P4MEDIUMCVSS 6.8v10.0\(1\)2014-07-14
CVE-2014-3319 [MEDIUM] CWE-22 CVE-2014-3319: Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communica Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup57676.
nvd
CVE-2008-1748P4HIGHCVSS 7.8≥ 4.1, < 4.1\(3\)sr7≥ 4.2, < 4.2\(3\)sr4+3 more2008-05-16
CVE-2008-1748 [HIGH] CWE-20 CVE-2008-1748: Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) does not properly validate SIP URLs, which allows remote attackers to cause a denial of service (service interruption) via a SIP INVITE message, aka Bug ID CSCsl22355.
nvd
CVE-2008-1745P4HIGHCVSS 7.8v4.1v4.2+4 more2008-05-16
CVE-2008-1745 [HIGH] CWE-20 CVE-2008-1745: Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote at Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (service interruption) via a SIP JOIN message with a malformed header, aka Bug ID CSCsi48115.
nvd
CVE-2010-0588P4HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0588 [HIGH] CVE-2010-0588: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdStatReq message with an invalid Line number, aka Bug ID CSCtc47823.
nvd
CVE-2011-0941P4HIGHCVSS 7.8v6.0v6.1\(1\)+49 more2011-11-01
CVE-2011-0941 [HIGH] CWE-399 CVE-2011-0941: Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)s Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj0917
nvd
CVE-2017-3877P4MEDIUMCVSS 6.5v11.5\(1.11.007.2\)2017-03-17
CVE-2017-3877 [MEDIUM] CWE-352 CVE-2017-3877: A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could all A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack against a user of the web interface of the affected software. More Information: CSCvb70021. Known Affected Releases: 11.5(1.11007.2).
nvd
CVE-2008-1747P4HIGHCVSS 7.8≥ 4.1, < 4.1\(3\)sr6≥ 4.2, < 4.2\(3\)sr3+3 more2008-05-16
CVE-2008-1747 [HIGH] CWE-20 CVE-2008-1747: Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4 Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x before 6.1(1) allows remote attackers to cause a denial of service (CCM service restart) via an unspecified SIP INVITE message, aka Bug ID CSCsk46944.
nvd
CVE-2007-5537P4HIGHCVSS 7.8≤ 5.1\(2\)2007-10-18
CVE-2007-5537 [HIGH] CWE-399 CVE-2007-5537: Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified Cal Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a denial of service (kernel panic) via a flood of SIP INVITE messages to UDP port 5060, which triggers resource exhaustion, aka CSCsi75822.
nvd
CVE-2014-0743P4MEDIUMCVSS 5.0≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-27
CVE-2014-0743 [MEDIUM] CWE-287 CVE-2014-0743: The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (U The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to bypass authentication and modify registered-device information via crafted data, aka Bug ID CSCum95468.
nvd
CVE-2019-12710P4MEDIUMCVSS 4.9v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-12710 [MEDIUM] CWE-89 CVE-2019-12710: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an authenticated, remote attacker to impact the confidentiality of an affected system by executing arbitrary SQL queries. The vulnerability exists because the affected software improp
nvd
CVE-2013-3461P4HIGHCVSS 7.1v9.0\(1\)v8.5+13 more2013-08-25
CVE-2013-3461 [HIGH] CWE-399 CVE-2013-3461: Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.
nvd
CVE-2013-1134P4HIGHCVSS 7.1v9.0\(1\)2013-02-27
CVE-2013-1134 [HIGH] CWE-287 CVE-2013-1134: The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communicati The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning attacks against transaction records, and cause a denial of service (bandwidth-pool consumption and
nvd
CVE-2014-0740P4MEDIUMCVSS 6.8≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-27
CVE-2014-0740 [MEDIUM] CWE-352 CVE-2014-0740: Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (C Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Administration component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of administrators for requests that make administrative changes, aka Bug ID CS
nvd
CVE-2018-0328P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-05-17
CVE-2018-0328 [MEDIUM] CWE-79 CVE-2018-0328: A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Prese A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed
nvd
CVE-2018-0355P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-06-07
CVE-2018-0355 [MEDIUM] CWE-20 CVE-2018-0355: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an un A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker to conduct a cross-frame scripting (XFS) attack against the user of the web UI of an affected system. The vulnerability is due to insufficient protections for HTML inline frames (iframes) by the web UI of the affected softw
nvd
CVE-2008-3800P4HIGHCVSS 7.1v4.1v5.0+2 more2008-09-26
CVE-2008-3800 [HIGH] CVE-2008-3800: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsu38644, a different vulnerability tha
nvd
CVE-2008-1743P4HIGHCVSS 7.8≥ 5.0, < 5.1\(3\)≥ 6.0, < 6.1\(1\)2008-05-16
CVE-2008-1743 [HIGH] CWE-399 CVE-2008-1743: Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Man Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, aka Bug ID CSCsi98433.
nvd
CVE-2008-3801P4HIGHCVSS 7.1v4.1v5.0+2 more2008-09-26
CVE-2008-3801 [HIGH] CVE-2008-3801: Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Communications Manager 4.1 through 6.1, when VoIP is configured, allows remote attackers to cause a denial of service (device or process reload) via unspecified valid SIP messages, aka Cisco Bug ID CSCsm46064, a different vulnerability tha
nvd
CVE-2008-2062P4MEDIUMCVSS 5.0≥ 4.2, < 4.2\(3\)sr4≥ 4.3, < 4.3\(2\)sr1+2 more2008-06-26
CVE-2008-2062 [MEDIUM] CWE-264 CVE-2008-2062: The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manage The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and 4.3 before 4.3(2)SR1, allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsq35151.
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase