cbcvebase.

Cisco Unified Communications Manager vulnerabilities

213 known vulnerabilities affecting cisco/unified_communications_manager.

Total CVEs
213
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1UNKNOWN6

Vulnerabilities

Page 9 of 11
CVE-2011-1604HIGHCVSS 7.1v6.0v6.1\(1\)+45 more2011-05-03
CVE-2011-1604 [HIGH] CWE-399 CVE-2011-1604: Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1( Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (memory consumption and process failure) via a malformed SIP message, aka Bug ID CSCti42904.
nvdcisco
CVE-2011-1605HIGHCVSS 7.8v6.0v6.1\(1\)+44 more2011-05-03
CVE-2011-1605 [HIGH] CVE-2011-1605: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6 Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCth39586.
nvdcisco
CVE-2011-1609HIGHCVSS 8.5PoCv6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1609 [HIGH] CWE-89 CVE-2011-1609: SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.
nvdcisco
CVE-2011-1607MEDIUMCVSS 6.5v6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1607 [MEDIUM] CWE-22 CVE-2011-1607: Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallMa Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.
nvdcisco
CVE-2011-1610MEDIUMCVSS 6.4v6.0v6.1\(1\)+46 more2011-05-03
CVE-2011-1610 [MEDIUM] CWE-89 CVE-2011-1610: Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server co Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or
nvdcisco
CVE-2010-3039MEDIUMCVSS 6.8PoCv6.0v6.1\(1\)+41 more2010-11-09
CVE-2010-3039 [MEDIUM] CWE-78 CVE-2010-3039: /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly Cal /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.
nvd
CVE-2010-2834HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+38 more2010-09-23
CVE-2010-2834 [HIGH] CVE-2010-2834: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)SU1, 7.x before 7.1(5), and 8.0 before 8.0(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via crafted SIP registration traffic ov
nvd
CVE-2010-2835HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+35 more2010-09-23
CVE-2010-2835 [HIGH] CVE-2010-2835: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allow remote attackers to cause a denial of service (device reload or voice-services ou
nvd
CVE-2010-2838HIGHCVSS 7.8≤ 7.0\(2a\)su2v7.0\(1\)su1+23 more2010-08-26
CVE-2010-2838 [HIGH] CVE-2010-2838: The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerl The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305.
nvdcisco
CVE-2010-2837HIGHCVSS 7.8≤ 6.1\(5\)v6.1\(1\)+38 more2010-08-26
CVE-2010-2837 [HIGH] CVE-2010-2837: The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallMa The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310.
nvdcisco
CVE-2010-0592HIGHCVSS 7.8v4.1v4.1\(3\)+46 more2010-03-05
CVE-2010-0592 [HIGH] CVE-2010-0592: The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.
nvdcisco
CVE-2010-0590HIGHCVSS 7.8v7.0v7.0\(1\)+3 more2010-03-05
CVE-2010-0590 [HIGH] CVE-2010-0590: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
nvdcisco
CVE-2010-0587HIGHCVSS 7.8v4.1v4.1\(3\)+48 more2010-03-05
CVE-2010-0587 [HIGH] CVE-2010-0587: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x befo Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.
nvdcisco
CVE-2010-0591HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0591 [HIGH] CVE-2010-0591: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
nvdcisco
CVE-2010-0588HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0588 [HIGH] CVE-2010-0588: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdStatReq message with an invalid Line number, aka Bug ID CSCtc47823.
nvdcisco
CVE-2009-2864HIGHCVSS 7.8v5.1\(1b\)v5.1\(1c\)+17 more2009-09-28
CVE-2009-2864 [HIGH] CVE-2009-2864: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
nvd
CVE-2009-2050HIGHCVSS 7.8fixed in 6.1\(1\)2009-08-27
CVE-2009-2050 [HIGH] CVE-2009-2050: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote at Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
nvdcisco
CVE-2009-2051HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+1 more2009-08-27
CVE-2009-2051 [HIGH] CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message t
nvdcisco
CVE-2009-2053HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+2 more2009-08-27
CVE-2009-2053 [HIGH] CVE-2009-2053: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2) allows remote attackers to cause a denial of service (file-descriptor exhaustion and SCCP outage) via a flood of TCP packets, aka Bug ID CSCsx32236.
nvdcisco
CVE-2009-2054HIGHCVSS 7.8≥ 4.0, < 5.1\(3g\)≥ 6.0, < 6.1\(4\)+2 more2009-08-27
CVE-2009-2054 [HIGH] CWE-770 CVE-2009-2054: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
nvdcisco