Cisco Unified Contact Center Enterprise vulnerabilities

8 known vulnerabilities affecting cisco/unified_contact_center_enterprise.

Total CVEs
8
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL3MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2025-20242CRITICALCVSS 9.1v12.6\(2\)es22025-05-21
CVE-2025-20242 [MEDIUM] CWE-284 CVE-2025-20242: A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) coul A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to read and modify data on an affected device. This vulnerability is due to a lack of proper authentication controls. An attacker could exploit this vulnerability by sending crafted TCP data to a specific po
nvd
CVE-2023-20058MEDIUMCVSS 6.1fixed in 12.5\(1\)_es02≥ 12.5\(2\), < 12.6\(1\)_es06+1 more2023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
nvd
CVE-2021-44228CRITICALCVSS 10.0KEVPoCfixed in 11.6\(2\)v11.6\(2\)+4 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2020-3163MEDIUMCVSS 5.9fixed in 12.5\(1\)2020-02-19
CVE-2020-3163 [MEDIUM] CWE-362 CVE-2020-3163: A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an un A vulnerability in the Live Data server of Cisco Unified Contact Center Enterprise could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability exists because the affected software improperly manages resources when processing inbound Live Data traffic. An attacker could exploit t
nvd
CVE-2017-6626MEDIUMCVSS 5.3v11.5\(1\)v11.6\(1\)2017-05-03
CVE-2017-6626 [MEDIUM] CWE-200 CVE-2017-6626: A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterpris A vulnerability in the Cisco Finesse Notification Service for Cisco Unified Contact Center Enterprise (UCCE) 11.5(1) and 11.6(1) could allow an unauthenticated, remote attacker to retrieve information from agents using the Finesse Desktop. The vulnerability is due to the existence of a user account that has an undocumented, hard-coded password. An att
nvd
CVE-2016-1439MEDIUMCVSS 6.1v4.6\(2\)v4.6.2+37 more2016-06-23
CVE-2016-1439 [MEDIUM] CWE-79 CVE-2016-1439: Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unified Contact Center Enterprise through 10.5(2) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux59650.
nvd
CVE-2007-5539CRITICALCVSS 9.0v7.1\(5\)2007-10-18
CVE-2007-5539 [CRITICAL] CVE-2007-5539: Unspecified vulnerability in Cisco Unified Intelligent Contact Management Enterprise (ICME), Unified Unspecified vulnerability in Cisco Unified Intelligent Contact Management Enterprise (ICME), Unified ICM Hosted (ICMH), Unified Contact Center Enterprise (UCCE), Unified Contact Center Hosted (UCCH), and System Unified Contact Center Enterprise (SUCCE) 7.1(5) allows remote authenticated users to gain privileges, and read reports or change the SUCCE configur
nvd
CVE-2007-0198MEDIUMCVSS 5.0≤ 7.1v5.02007-01-11
CVE-2007-0198 [MEDIUM] CVE-2007-0198: The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.
nvd