Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 8 of 11
CVE-2007-3775P4HIGHCVSS 7.8v5.0v5.1\(1\)+1 more2007-07-15
CVE-2007-3775 [HIGH] CVE-2007-3775: Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and U
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allows remote attackers to cause a denial of service (loss of cluster services) via unspecified vectors, aka (1) CSCsj09859 and (2) CSCsj19985.
nvd
CVE-2022-20862P4MEDIUMCVSS 4.3fixed in 12.5\(1\)su6≥ 14.0, < 14su22022-07-06
CVE-2022-20862 [MEDIUM] CWE-23 CVE-2022-20862: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. This vulnerability is due to imp
nvd
CVE-2014-0736P4MEDIUMCVSS 6.8≤ 10.0\(1\)v3.3\(5\)+16 more2014-02-20
CVE-2014-0736 [MEDIUM] CWE-352 CVE-2014-0736: Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (C
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to hijack the authentication of arbitrary users for requests that make CAR modifications, aka Bug ID CSCum46468.
nvd
CVE-2017-3821P4MEDIUMCVSS 6.1v10.5\(2.14076.1\)2017-02-22
CVE-2017-3821 [MEDIUM] CWE-79 CVE-2017-3821: A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an un
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.209) 12.0(0.98000.478) 12.0(0.98000.609).
nvd
CVE-2018-0267P4MEDIUMCVSS 6.5v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-04-19
CVE-2018-0267 [MEDIUM] CWE-200 CVE-2018-0267: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view sensitive data that should be restricted. This could include LDAP credentials. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by b
nvd
CVE-2017-3872P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v10.5\(2.14076.1\)+2 more2017-03-17
CVE-2017-3872 [MEDIUM] CWE-79 CVE-2017-3872: A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Ci
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct XSS attacks against a user of an affected device. More Information: CSCvc21620. Known Affected Releases: 10.5(2.14076.1). Known Fixed Releases: 12.0(0.98000.641
nvd
CVE-2017-3802P4MEDIUMCVSS 6.1v12.0\(0.99000.9\)2017-01-26
CVE-2017-3802 [MEDIUM] CWE-79 CVE-2017-3802: A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attac
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCvc20679. Known Affected Releases: 12.0(0.99000.9). Known Fixed Releases: 12.0(0.98000.176) 12.0(0.98000.414) 12.0(0.98000.5
nvd
CVE-2021-1407P4MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1407 [MEDIUM] CWE-89 CVE-2021-1407: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1409P4MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1409 [MEDIUM] CWE-89 CVE-2021-1409: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1380P4MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1380 [MEDIUM] CWE-89 CVE-2021-1380: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1408P4MEDIUMCVSS 6.1fixed in 142021-04-08
CVE-2021-1408 [MEDIUM] CWE-89 CVE-2021-1408: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2022-20788P4MEDIUMCVSS 6.1≥ 11.5\(1\), < 11.5\(1\)su11≥ 12.5\(1\), < 12.5\(1\)su6+1 more2022-04-21
CVE-2022-20788 [MEDIUM] CWE-79 CVE-2022-20788: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists b
nvd
CVE-2022-20815P4MEDIUMCVSS 6.1≥ 14.0, < 14su22022-07-06
CVE-2022-20815 [MEDIUM] CWE-79 CVE-2022-20815: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains
nvd
CVE-2022-20800P4MEDIUMCVSS 6.1≥ 11.5\(1\), < 14su22022-07-06
CVE-2022-20800 [MEDIUM] CWE-79 CVE-2022-20800: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc
nvd
CVE-2023-20242P4MEDIUMCVSS 6.1v11.5\(1\)v12.5\(1\)+1 more2023-08-16
CVE-2023-20242 [MEDIUM] CWE-79 CVE-2023-20242: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack agains
nvd
CVE-2024-20511P4MEDIUMCVSS 6.1v12.0\(1\)su1v12.0\(1\)su2+15 more2024-11-06
CVE-2024-20511 [MEDIUM] CWE-79 CVE-2024-20511: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.
This vulnerability exists becau
nvd
CVE-2018-0340P4MEDIUMCVSS 5.4v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-06-07
CVE-2018-0340 [MEDIUM] CWE-79 CVE-2018-0340: A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) softwa
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability is due to insufficient input validation of certain parameters passed to the we
nvd
CVE-2017-3888P4MEDIUMCVSS 5.4v12.0\(0.98000.452\)2017-04-07
CVE-2017-3888 [MEDIUM] CWE-79 CVE-2017-3888: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability affects Cisco Unified Communications Manager with a default con
nvd
CVE-2022-20804P4MEDIUMCVSS 6.5≤ 14.02022-04-21
CVE-2022-20804 [MEDIUM] CWE-754 CVE-2022-20804: A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM)
A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, adjacent attacker to cause a kernel panic on an affected system, resulting in a denial of service (DoS) condition. This vulnerability
nvd
CVE-2018-0206P4MEDIUMCVSS 6.1v11.5\(1.13900.52\)2018-02-22
CVE-2018-0206 [MEDIUM] CWE-79 CVE-2018-0206: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by th
nvd