cbcvebase.

Cisco Unified Communications Manager vulnerabilities

208 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1

Vulnerabilities

Page 7 of 11
CVE-2008-1744P4HIGHCVSS 7.8v4.2_3_sr2v4.2_3_sr2b+13 more2008-05-16
CVE-2008-1744 [HIGH] CWE-20 CVE-2008-1744: The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUC The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, and 4.3 before 4.3(2) allows remote attackers to cause a denial of service (service crash) via malformed network traffic, aka Bug ID CSCsk46770.
nvd
CVE-2022-20752P4MEDIUMCVSS 5.3≥ 12.5\(1\), < 12.5\(1\)su6≥ 14.0, < 14su12022-07-06
CVE-2022-20752 [MEDIUM] CWE-208 CVE-2022-20752: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exp
nvd
CVE-2008-2730P4MEDIUMCVSS 5.0v5.1v6.12008-06-26
CVE-2008-2730 [MEDIUM] CWE-287 CVE-2008-2730: The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manage The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and 6.x before 6.1(1) allows remote attackers to bypass authentication, and obtain cluster configuration information and statistics, via a direct TCP connection to the service port, aka Bug ID CSCsj90843.
nvd
CVE-2021-1282P4MEDIUMCVSS 4.9fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1282 [MEDIUM] CWE-35 CVE-2021-1282: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2021-1364P4MEDIUMCVSS 4.9fixed in 11.5\(1\)su9≥ 12.0, < 12.0\(1\)su4+1 more2021-01-20
CVE-2021-1364 [MEDIUM] CWE-35 CVE-2021-1364: Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system. One of the SQL injection vulnerabilities that affects Unified CM IM&P also affects Cisco Unified Communications Manager (Unified CM) and Cisco
nvd
CVE-2011-2561P4HIGHCVSS 7.1v7.0\(1\)su1v7.0\(1\)su1a+25 more2011-08-29
CVE-2011-2561 [HIGH] CWE-399 CVE-2011-2561: The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termination Point (MTP), which allows remote attackers to cause a denial of service (service outage)
nvd
CVE-2018-0411P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-08-01
CVE-2018-0411 [MEDIUM] CWE-79 CVE-2018-0411: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by th
nvd
CVE-2014-0724P4MEDIUMCVSS 4.0≤ 10.0\(1\)v10.02014-02-13
CVE-2014-0724 [MEDIUM] CWE-20 CVE-2014-0724: The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to bypass authentication and read arbitrary files by using an unspecified prompt, aka Bug ID CSCum05340.
nvd
CVE-2008-1742P4HIGHCVSS 7.8v4.1v4.2+4 more2008-05-16
CVE-2008-1742 [HIGH] CWE-399 CVE-2008-1742: Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Man Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) allows remote attackers to cause a denial of service (memory consumption and service interruption) via a series of malformed TCP packets, as demonstrated by TCPFUZZ, aka Bug ID CSCsj80609.
nvd
CVE-2014-0732P4MEDIUMCVSS 5.0≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-20
CVE-2014-0732 [MEDIUM] CWE-287 CVE-2014-0732: The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unifie The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not properly enforce authentication requirements, which allows remote attackers to read application files via a direct request to a URL, aka Bug ID CSCum46495.
nvd
CVE-2011-1604P4HIGHCVSS 7.1v6.0v6.1\(1\)+45 more2011-05-03
CVE-2011-1604 [HIGH] CWE-399 CVE-2011-1604: Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1( Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.
nvd
CVE-2016-6440P4MEDIUMCVSS 6.5v11.5\(0.99838.4\)2016-10-27
CVE-2016-6440 [MEDIUM] CWE-20 CVE-2016-6440: The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed insi The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed inside an iframe within a web page, which in turn could lead to a clickjacking attack. More Information: CSCuz64683 CSCuz64698. Known Affected Releases: 11.0(1.10000.10), 11.5(1.10000.6), 11.5(0.99838.4). Known Fixed Releases: 11.0(1.22048.1), 11.5(0.98000.1
nvd
CVE-2016-9206P4MEDIUMCVSS 6.1v11.5\(1.10000.6\)2016-12-14
CVE-2016-9206 [MEDIUM] CWE-79 CVE-2016-9206: A vulnerability in the ccmadmin page of Cisco Unified Communications Manager (CUCM) could allow an u A vulnerability in the ccmadmin page of Cisco Unified Communications Manager (CUCM) could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvb64641. Known Affected Releases: 11.5(1.10000.6) 11.5(1.11007.2). Known Fixed Releases: 11.5(1.12900.7) 11.5(1.12900.8) 12.0(0.98000.155) 12.0(
nvd
CVE-2017-6654P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-05-22
CVE-2017-6654 [MEDIUM] CWE-79 CVE-2017-6654: A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 t A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 through 11.5 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied in
nvd
CVE-2017-3829P4MEDIUMCVSS 6.1v11.0\(1.10000.10\)v11.5\(1.10000.6\)2017-02-22
CVE-2017-3829 [MEDIUM] CWE-79 CVE-2017-3829: A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switch A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvc30999. Known Affected Releases: 12.0(0.98000.280). Known
nvd
CVE-2017-3828P4MEDIUMCVSS 6.1v11.0\(1.10000.10\)v11.5\(1.10000.6\)2017-02-22
CVE-2017-3828 [MEDIUM] CWE-79 CVE-2017-3828: A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switch A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. More Information: CSCvb98777. Known Affected Releases: 11.0(1.10000.10) 11.5(1.1
nvd
CVE-2016-6472P4MEDIUMCVSS 6.1v11.5\(1.2\)2016-11-19
CVE-2016-6472 [MEDIUM] CWE-79 CVE-2016-6472: A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (Cal A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unauthenticated, remote attacker to launch a cross-site scripting (XSS) attack against a user of the web interface on the affected system. More Information: CSCvb37121. Known Affected Releases: 11.5(1.2). Known Fixed Releases: 11
nvd
CVE-2014-3317P4MEDIUMCVSS 5.5v10.0\(1\)2014-07-14
CVE-2014-3317 [MEDIUM] CWE-22 CVE-2014-3317: Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) compo Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager 10.0(1) allows remote authenticated users to delete arbitrary files via a crafted URL, aka Bug ID CSCup76314.
nvd
CVE-2015-0749P4MEDIUMCVSS 6.1≤ 10.5\(2.10000.5\)2020-02-19
CVE-2015-0749 [MEDIUM] CWE-79 CVE-2015-0749: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attac A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on the affected software. The vulnerabilities is due to improper input validation of certain parameters passed to the affected software. An attacker could exploit this vulnerability by convincing a user
nvd
CVE-2024-20488P4MEDIUMCVSS 6.1v12.5\(1\)v12.5\(1\)su1+19 more2024-08-21
CVE-2024-20488 [MEDIUM] CWE-79 CVE-2024-20488: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists becau
nvd
Cisco Unified Communications Manager vulnerabilities | cvebase