Cisco Unified Communications Manager vulnerabilities

207 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
207
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1

Vulnerabilities

Page 8 of 11
CVE-2013-3434MEDIUMCVSS 6.8v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3434 [MEDIUM] CVE-2013-3434: Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9. Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCui02242.
nvd
CVE-2013-3403MEDIUMCVSS 6.8v7.1\(2a\)v7.1\(2a\)su1+53 more2013-07-18
CVE-2013-3403 [MEDIUM] CVE-2013-3403: Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified file-permission and environment-variable issues for privileged programs, aka Bug ID CSCuh73454.
nvd
CVE-2013-4869UNKNOWNCVSS 0.0≥ 7.1\(1\), ≤ 9.1\(2\)2013-07-18
CVE-2013-4869 [NONE] CWE-522 CVE-2013-4869: Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in C Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encryption key across different customers' installations, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge
nvd
CVE-2013-1134HIGHCVSS 7.1v9.0\(1\)2013-02-27
CVE-2013-1134 [HIGH] CWE-287 CVE-2013-1134: The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communicati The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the remote LBM Hub node, which allows remote attackers to conduct cache-poisoning attacks against transaction records, and cause a denial of service (bandwidth-pool consumption and
nvd
CVE-2013-1133HIGHCVSS 7.8v8.6v8.6\(1\)+6 more2013-02-27
CVE-2013-1133 [HIGH] CWE-20 CVE-2013-1133: Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remote attackers to cause a denial of service (CPU consumption and GUI and voice outages) via malformed packets to unused UDP ports, aka Bug ID CSCtx43337.
nvd
CVE-2012-3949HIGHCVSS 7.8v6.0\(1a\)v6.0\(1b\)+37 more2012-09-27
CVE-2012-3949 [HIGH] CWE-20 CVE-2012-3949: The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a cra
nvd
CVE-2011-4019MEDIUMCVSS 5.4v7.0v7.0\(1\)+31 more2012-05-03
CVE-2011-4019 [MEDIUM] CWE-399 CVE-2011-4019: Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers to cause a denial of service (memory consumption) via a crafted response to a SIP SUBSCRIBE message, aka Bug IDs CSCto93837 and CSCtj61883.
nvd
CVE-2012-0376MEDIUMCVSS 5.0v8.52012-05-03
CVE-2012-0376 [MEDIUM] CVE-2012-0376: The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attack The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of service (core dump) via vectors involving SIP messages that arrive after an upgrade, aka Bug ID CSCtj87367.
nvd
CVE-2011-4486HIGHCVSS 7.8v6.0v6.0\(1\)+68 more2012-03-01
CVE-2011-4486 [HIGH] CWE-399 CVE-2011-4486: Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allow remote attackers to cause a denial of service (device reload) via a crafted SCCP registration,
nvd
CVE-2011-4487MEDIUMCVSS 6.8v6.0v6.0\(1\)+68 more2012-03-01
CVE-2011-4487 [MEDIUM] CWE-89 CVE-2011-4487: SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 before 8.6(2a)su1 and Cisco Business Edition 3000 with software before 8.6.3 and 5000 and 6000 with software before 8.6(2a)su1 allows remote attackers to execute arbitrary SQL commands via a craf
nvd
CVE-2011-0941HIGHCVSS 7.8v6.0v6.1\(1\)+49 more2011-11-01
CVE-2011-0941 [HIGH] CWE-399 CVE-2011-0941: Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)s Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1), and Cisco IOS 12.4 and 15.1, allows remote attackers to cause a denial of service (memory consumption and process failure or device reload) via a malformed SIP message, aka Bug IDs CSCti75128 and CSCtj0917
nvd
CVE-2011-3315HIGHCVSS 7.8PoCv5.0v5.1+60 more2011-10-27
CVE-2011-3315 [HIGH] CWE-22 CVE-2011-3315: Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)SU2, and 8.x before 8.0(3), and Cisco Unified Contact Center Express (aka Unified CCX or UCCX) and Cisco Unified IP Interactive Voice Response (Unified IP-IVR) before 6.0(1)SR1ES8, 7.0(x) before 7.0(2)ES1, 8.0(x) through 8.0(2)S
nvd
CVE-2011-2072HIGHCVSS 7.8v6.0v6.1\(1\)+55 more2011-10-03
CVE-2011-2072 [HIGH] CWE-399 CVE-2011-2072: Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified C Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su4, 8.x before 8.5(1)su2, and 8.6 before 8.6(1) allows remote attackers to cause a denial of service (memory consumption and device reload or process failure) via a malformed SIP message, aka Bug IDs
nvd
CVE-2011-1643CRITICALCVSS 10.0v6.0v6.1\(1\)+46 more2011-08-29
CVE-2011-1643 [CRITICAL] CWE-200 CVE-2011-1643: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8. Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 and Cisco Unified Presence Server 6.x, 7.x, 8.0, and 8.5 before 8.5xnr allow remote attackers to read database data by connecting to a query interface through an SSL session, aka Bug IDs CSCti81574, CSCto63060, CSCto72183,
nvd
CVE-2011-2560HIGHCVSS 7.8v4.1\(3\)v4.1\(3\)sr1+12 more2011-08-29
CVE-2011-2560 [HIGH] CWE-399 CVE-2011-2560: The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle idle TCP connections, which allows remote attackers to cause a denial of service (memory consumption and restart) by making many connections, aka Bug ID CSCtf97162.
nvd
CVE-2011-2564HIGHCVSS 7.8v8.0v8.0\(1\)+7 more2011-08-29
CVE-2011-2564 [HIGH] CVE-2011-2564: Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communicatio Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth19417.
nvd
CVE-2011-2563HIGHCVSS 7.8v8.0v8.0\(1\)+7 more2011-08-29
CVE-2011-2563 [HIGH] CVE-2011-2563: Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communicatio Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 8.x before 8.5(1) and Cisco Intercompany Media Engine 8.x before 8.5(1) allows remote attackers to cause a denial of service (device reload) via crafted SAF packets, aka Bug ID CSCth26669.
nvd
CVE-2011-2562HIGHCVSS 7.8v6.0v6.1\(1\)+46 more2011-08-29
CVE-2011-2562 [HIGH] CVE-2011-2562: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6 Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (service outage) via a SIP INVITE message, aka Bug ID CSCth43256.
nvd
CVE-2011-2561HIGHCVSS 7.1v7.0\(1\)su1v7.0\(1\)su1a+25 more2011-08-29
CVE-2011-2561 [HIGH] CWE-399 CVE-2011-2561: The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(1) does not properly handle SDP data within a SIP call in certain situations related to use of the g729ar8 codec for a Media Termination Point (MTP), which allows remote attackers to cause a denial of service (service outage)
nvd
CVE-2011-1604HIGHCVSS 7.1v6.0v6.1\(1\)+45 more2011-05-03
CVE-2011-1604 [HIGH] CWE-399 CVE-2011-1604: Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1( Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.
nvd