Cisco Unified Communications Manager vulnerabilities
207 known vulnerabilities affecting cisco/unified_communications_manager.
Total CVEs
207
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
1
Severity breakdown
CRITICAL12HIGH76MEDIUM117LOW1
Vulnerabilities
Page 9 of 11
CVE-2011-1605HIGHCVSS 7.8v6.0v6.1\(1\)+44 more2011-05-03
CVE-2011-1605 [HIGH] CVE-2011-1605: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su2, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCth39586.
nvd
CVE-2011-1609HIGHCVSS 8.5PoCv6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1609 [HIGH] CWE-89 CVE-2011-1609: SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager)
SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCtg85647.
nvd
CVE-2011-1606HIGHCVSS 7.8v6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1606 [HIGH] CVE-2011-1606: Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x before 7.1(5)su1, 8.0 before 8.0(3), and 8.5 before 8.5(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtg62855.
nvd
CVE-2011-1610MEDIUMCVSS 6.4v6.0v6.1\(1\)+46 more2011-05-03
CVE-2011-1610 [MEDIUM] CWE-89 CVE-2011-1610: Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server co
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5)su4, 8.0 before 8.0(3a)su2, and 8.5 before 8.5(1)su1 allow remote attackers to execute arbitrary SQL commands via the (1) f, (2) l, or
nvd
CVE-2011-1607MEDIUMCVSS 6.5v6.0v6.1\(1\)+43 more2011-05-03
CVE-2011-1607 [MEDIUM] CWE-22 CVE-2011-1607: Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallMa
Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3, 8.0 before 8.0(3a)su1, and 8.5 before 8.5(1) allows remote authenticated users to upload files to arbitrary directories via a modified pathname in an upload request, aka Bug ID CSCti81603.
nvd
CVE-2010-3039MEDIUMCVSS 6.8PoCv6.0v6.1\(1\)+41 more2010-11-09
CVE-2010-3039 [MEDIUM] CWE-78 CVE-2010-3039: /usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly Cal
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in a request to the administrative interface, aka Bug IDs CSCti52041 and CSCti74930.
nvd
CVE-2010-2834HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+38 more2010-09-23
CVE-2010-2834 [HIGH] CVE-2010-2834: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)SU1, 7.x before 7.1(5), and 8.0 before 8.0(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via crafted SIP registration traffic ov
nvd
CVE-2010-2835HIGHCVSS 7.8v6.0v6.0\(1.2114.1\)+35 more2010-09-23
CVE-2010-2835 [HIGH] CVE-2010-2835: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.0 before 7.0(2a)su3, 7.1su before 7.1(3b)su2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allow remote attackers to cause a denial of service (device reload or voice-services ou
nvd
CVE-2010-2838HIGHCVSS 7.8≤ 7.0\(2a\)su2v7.0\(1\)su1+23 more2010-08-26
CVE-2010-2838 [HIGH] CVE-2010-2838: The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerl
The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305.
nvd
CVE-2010-2837HIGHCVSS 7.8≤ 6.1\(5\)v6.1\(1\)+38 more2010-08-26
CVE-2010-2837 [HIGH] CVE-2010-2837: The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallMa
The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310.
nvd
CVE-2010-0592HIGHCVSS 7.8v4.1v4.1\(3\)+46 more2010-03-05
CVE-2010-0592 [HIGH] CVE-2010-0592: The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x
The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before 6.1(3), 7.0x before 7.0(2), 7.1x before 7.1(2), and 8.x before 8.0(1) allows remote attackers to cause a denial of service (service failure) via a malformed message, aka Bug ID CSCsu31800.
nvd
CVE-2010-0591HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0591 [HIGH] CVE-2010-0591: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REG message, related to an overflow of the Telephone-URL field, aka Bug ID CSCtc62362.
nvd
CVE-2010-0587HIGHCVSS 7.8v4.1v4.1\(3\)+48 more2010-03-05
CVE-2010-0587 [HIGH] CVE-2010-0587: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x befo
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP StationCapabilitiesRes message with an invalid MaxCap field, aka Bug ID CSCtc38985.
nvd
CVE-2010-0588HIGHCVSS 7.8v6.0v6.0\(1\)+16 more2010-03-05
CVE-2010-0588 [HIGH] CVE-2010-0588: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SCCP (1) RegAvailableLines or (2) FwdStatReq message with an invalid Line number, aka Bug ID CSCtc47823.
nvd
CVE-2010-0590HIGHCVSS 7.8v7.0v7.0\(1\)+3 more2010-03-05
CVE-2010-0590 [HIGH] CVE-2010-0590: The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager)
The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP Register message, aka Bug ID CSCtc37188.
nvd
CVE-2009-2864HIGHCVSS 7.8v5.1\(1b\)v5.1\(1c\)+17 more2009-09-28
CVE-2009-2864 [HIGH] CVE-2009-2864: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x before 7.1(2) allows remote attackers to cause a denial of service (service restart) via malformed SIP messages, aka Bug ID CSCsz95423.
nvd
CVE-2009-2051HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+1 more2009-08-27
CVE-2009-2051 [HIGH] CVE-2009-2051: Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Ci
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), and 7.x before 7.1(2) allow remote attackers to cause a denial of service (device reload or voice-services outage) via a malformed SIP INVITE message t
nvd
CVE-2009-2052HIGHCVSS 7.8≥ 5.0, < 5.1\(3g\)≥ 6.1\(1\), < 6.1\(4\)+2 more2009-08-27
CVE-2009-2052 [HIGH] CVE-2009-2052: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2), and 7.1 before 7.1(2); and Cisco Unified Presence 1.x, 6.x before 6.0(6), and 7.x before 7.0(4); allows remote attackers to cause a denial of service (TCP services outage) via a large number of TCP connections, related to "trackin
nvd
CVE-2009-2050HIGHCVSS 7.8fixed in 6.1\(1\)2009-08-27
CVE-2009-2050 [HIGH] CVE-2009-2050: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote at
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of service (voice-services outage) via a malformed header in a SIP message, aka Bug ID CSCsi46466.
nvd
CVE-2009-2054HIGHCVSS 7.8≥ 4.0, < 5.1\(3g\)≥ 6.0, < 6.1\(4\)+2 more2009-08-27
CVE-2009-2054 [HIGH] CWE-770 CVE-2009-2054: Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x b
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2a)su1, and 7.1 before 7.1(2a)su1 allows remote attackers to cause a denial of service (file-descriptor exhaustion and SIP outage) via a flood of TCP packets, aka Bug ID CSCsx23689.
nvd