Cisco Unified Communications Manager vulnerabilities
208 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
208
CISA KEV
3
actively exploited
Public exploits
8
Exploited in wild
4
Severity breakdown
CRITICAL12HIGH77MEDIUM117LOW1
Vulnerabilities
Page 9 of 11
CVE-2017-3798P4MEDIUMCVSS 6.1v11.5\(1.12000.1\)2017-01-26
CVE-2017-3798 [MEDIUM] CWE-79 CVE-2017-3798: A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Ci
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Information: CSCvb97237. Known Affected Releases: 11.0(1.10000.10) 11.5(1.10000.6). Known Fixed Releases: 1
nvd
CVE-2017-3833P4MEDIUMCVSS 6.1v12.0\(0.99999.2\)2017-02-22
CVE-2017-3833 [MEDIUM] CWE-79 CVE-2017-3833: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthen
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of the affected software. More Information: CSCvb95951. Known Affected Releases: 12.0(0.99999.2). Known Fixed Releases: 11.0(1.23064.1) 11.5(1.120
nvd
CVE-2019-12715P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-12715 [MEDIUM] CWE-79 CVE-2019-12715: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insu
nvd
CVE-2019-12707P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-12707 [MEDIUM] CWE-79 CVE-2019-12707: A vulnerability in the web-based interface of multiple Cisco Unified Communications products could a
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based inte
nvd
CVE-2019-12716P4MEDIUMCVSS 6.1v10.5\(2.10000.5\)v11.5\(1.10000.6\)+2 more2019-10-02
CVE-2019-12716 [MEDIUM] CWE-79 CVE-2019-12716: A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. The vulnerability is due to insufficient validation of us
nvd
CVE-2020-3346P4MEDIUMCVSS 6.1≥ 10.5\(2\), ≤ 10.5\(2\)su10≥ 11.5\(1\), ≤ 11.5\(1\)su8+2 more2020-08-17
CVE-2020-3346 [MEDIUM] CWE-79 CVE-2020-3346: A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. The vulnerability exists because the web UI does not prope
nvd
CVE-2020-3282P4MEDIUMCVSS 6.1≥ 10.5\(2\), < 10.5\(2\)su10≥ 11.5\(1\), < 11.5\(1\)su8+2 more2020-07-02
CVE-2020-3282 [MEDIUM] CWE-79 CVE-2020-3282: A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us
nvd
CVE-2023-20116P4MEDIUMCVSS 5.7v11.5\(1.10000.6\)v12.0\(1.10000.10\)+2 more2023-06-28
CVE-2023-20116 [MEDIUM] CWE-835 CVE-2023-20116: A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Mana
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to insuff
nvd
CVE-2018-15403P4MEDIUMCVSS 5.4v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-10-05
CVE-2018-15403 [MEDIUM] CWE-601 CVE-2018-15403: A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Mana
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the paramete
nvd
CVE-2021-1406P4MEDIUMCVSS 4.9v10.5\(2\)v10.5\(2\)su1+29 more2021-04-08
CVE-2021-1406 [MEDIUM] CWE-538 CVE-2021-1406: A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communication
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to access sensitive information on an affected device. The vulnerability is due to improper inclusion of sensitive information in downloadable files. An
nvd
CVE-2021-34701P4MEDIUMCVSS 4.3fixed in 14su12021-11-04
CVE-2021-34701 [MEDIUM] CWE-22 CVE-2021-34701: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access s
nvd
CVE-2013-6689P4MEDIUMCVSS 6.9≤ 9.1\(1\)v3.3\(5\)+111 more2013-11-18
CVE-2013-6689 [MEDIUM] CWE-20 CVE-2013-6689: Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass fi
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229.
nvd
CVE-2017-12357P4MEDIUMCVSS 5.4v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2017-11-30
CVE-2017-12357 [MEDIUM] CWE-79 CVE-2017-12357: A vulnerability in the web-based management interface of Cisco Unified Communications Manager could
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-base
nvd
CVE-2014-3318P4MEDIUMCVSS 4.0v10.0\(1\)_base2014-07-10
CVE-2014-3318 [MEDIUM] CWE-20 CVE-2014-3318: Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) com
Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via a crafted URL, aka Bug ID CSCup76318.
nvd
CVE-2018-0266P4MEDIUMCVSS 4.3v10.5\(2.10000.5\)v11.0\(1.10000.10\)+2 more2018-04-19
CVE-2018-0266 [MEDIUM] CWE-200 CVE-2018-0266: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view sensitive data. The vulnerability is due to insufficient protection of database tables over the web interface. An attacker could exploit this vulnerability by browsing to a specific URL. An exploit could allow the attacker
nvd
CVE-2017-6785P4MEDIUMCVSS 4.3v10.5\(2.10000.5\)v11.0\(1.10000.10\)+1 more2017-08-17
CVE-2017-6785 [MEDIUM] CWE-20 CVE-2017-6785: A vulnerability in configuration modification permissions validation for Cisco Unified Communication
A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allow an authenticated, remote attacker to perform a horizontal privilege escalation where one user can modify another user's configuration. The vulnerability is due to lack of proper Role Based Access Control (RBAC) when certain user con
nvd
CVE-2018-0120P4MEDIUMCVSS 4.3v11.5\(1.13900.52\)2018-02-08
CVE-2018-0120 [MEDIUM] CWE-89 CVE-2018-0120: A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenti
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerability exists because the affected software fails to validate user-supplied input in certain SQL queries that bypass protection filters. An attacker could ex
nvd
CVE-2017-3874P4MEDIUMCVSS 5.4v11.5\(1.11007.2\)2017-03-17
CVE-2017-3874 [MEDIUM] CWE-79 CVE-2017-3874: A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could all
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. More Information: CSCvb70033. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.507) 11.0(1.23900.5) 11.0(1.23900.3) 10.5(2.15900.2).
nvd
CVE-2015-4206P4MEDIUMCVSS 4.3v8.0\(2c\)v8.0\(3\)+6 more2015-12-15
CVE-2015-4206 [MEDIUM] CWE-79 CVE-2015-4206: Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a crafted parameter, aka Bug ID CSCuu15266.
nvd
CVE-2017-3836P4MEDIUMCVSS 4.3v11.5\(1.11007.2\)2017-02-22
CVE-2017-3836 [MEDIUM] CWE-200 CVE-2017-3836: A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthentic
A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view sensitive data. More Information: CSCvb61689. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.162) 12.0(0.98000.178) 12.0(0.98000.383) 12.0(0.98000.488) 12.0(0.98000.536) 12.0(0.98000.6) 12.0(0.
nvd