cbcvebase.

Cisco Unified Contact Center Express vulnerabilities

45 known vulnerabilities affecting cisco/unified_contact_center_express.

Total CVEs
45
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL7HIGH16MEDIUM22

Vulnerabilities

Page 2 of 3
CVE-2016-6427P3HIGHCVSS 8.8v10.0\(1\)v10.5\(1\)+2 more2016-10-06
CVE-2016-6427 [HIGH] CWE-352 CVE-2016-6427: Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 th Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
nvd
CVE-2020-3267P3HIGHCVSS 7.1fixed in 12.5\(1\)2020-06-03
CVE-2020-3267 [HIGH] CWE-285 CVE-2020-3267: A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could all A vulnerability in the API subsystem of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to change the availability state of any agent. The vulnerability is due to insufficient authorization enforcement on an affected system. An attacker could exploit this vulnerability by authenticating to an affected sys
nvd
CVE-2025-20278P3MEDIUMCVSS 6.7v8.5\(1\)v9.0\(2\)su3es04+58 more2025-06-04
CVE-2025-20278 [MEDIUM] CWE-77 CVE-2025-20278: A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenti A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerab
nvd
CVE-2025-20277P3MEDIUMCVSS 6.7v8.5\(1\)v9.0\(2\)su3es04+58 more2025-06-04
CVE-2025-20277 [MEDIUM] CWE-22 CVE-2025-20277: A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authentica A vulnerability in the web-based management interface of Cisco Unified CCX could allow an authenticated, local attacker to execute arbitrary code on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper limitation of a pathname to a restricted directory (path
nvd
CVE-2025-20374P3MEDIUMCVSS 4.9fixed in 12.5\(1\)_su03_es07v15.02025-11-05
CVE-2025-20374 [MEDIUM] CWE-22 CVE-2025-20374: A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory traversal and access arbitrary resources. This vulnerability is due to an insufficient input validation associated to specific UI features. An attacker could exploit this vulnerability by sending a crafted request to the web UI. A s
nvd
CVE-2010-1570P4HIGHCVSS 7.8v5.0v6.0+1 more2010-06-10
CVE-2010-1570 [HIGH] CVE-2010-1570: The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (U The computer telephony integration (CTI) server component in Cisco Unified Contact Center Express (UCCX) 7.0 before 7.0(1)SR4 and 7.0(2), 6.0 before 6.0(1)SR1, and 5.0 before 5.0(2)SR3 allows remote attackers to cause a denial of service (CTI server and Node Manager failure) via a malformed CTI message.
nvd
CVE-2025-20288P3MEDIUMCVSS 5.3v10.5\(1\)v10.5\(1\)su1+54 more2025-07-16
CVE-2025-20288 [MEDIUM] CWE-918 CVE-2025-20288: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability
nvd
CVE-2023-20232P4MEDIUMCVSS 5.3fixed in 12.5\(1\)_su2_es052023-08-16
CVE-2023-20232 [MEDIUM] CWE-20 CVE-2023-20232: A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) A vulnerability in the Tomcat implementation for Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to cause a web cache poisoning attack on an affected device. This vulnerability is due to improper input validation of HTTP requests. An attacker could exploit this vulnerability by sending crafted HTTP re
nvd
CVE-2017-6722P4MEDIUMCVSS 6.1v11.5\(1\)v11.5.1es01+1 more2017-07-04
CVE-2017-6722 [MEDIUM] CWE-287 CVE-2017-6722: A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Co A vulnerability in the Extensible Messaging and Presence Protocol (XMPP) service of Cisco Unified Contact Center Express (UCCx) could allow an unauthenticated, remote attacker to masquerade as a legitimate user, aka a Clear Text Authentication Vulnerability. More Information: CSCuw86638. Known Affected Releases: 10.6(1). Known Fixed Releases: 11.5(1.1
nvd
CVE-2026-20117P4MEDIUMCVSS 6.1≤ 15.0\(1\)ES012026-03-11
CVE-2026-20117 [MEDIUM] CWE-79 CVE-2026-20117: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability exists because the web-based management interface of an affected system does not sufficiently val
nvd
CVE-2025-20129P4MEDIUMCVSS 5.4v8.5\(1\)v9.0\(2\)su3es04+58 more2025-06-04
CVE-2025-20129 [MEDIUM] CWE-200 CVE-2025-20129: A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), form A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could
nvd
CVE-2019-15259P4MEDIUMCVSS 6.1fixed in 11.6\(2\)v12.0\(1\)2019-10-02
CVE-2019-15259 [MEDIUM] CWE-113 CVE-2019-15259: A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticat A vulnerability in Cisco Unified Contact Center Express (UCCX) Software could allow an unauthenticated, remote attacker to conduct an HTTP response splitting attack. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server of the affected system. An attacker could exploit this vulnerability by co
nvd
CVE-2019-15278P4MEDIUMCVSS 6.1v12.0\(1\)2020-01-26
CVE-2019-15278 [MEDIUM] CWE-79 CVE-2019-15278: A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticate A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to bypass authorization and access sensitive information related to the device. The vulnerability exists because the software fails to sanitize URLs before it handles requests. An attacker could exploit this vulnerability by submitti
nvd
CVE-2021-1463P4MEDIUMCVSS 6.1≤ 12.0\(1\)≥ 12.5\(1\), < 12.5\(1\)su12021-04-08
CVE-2021-1463 [MEDIUM] CWE-79 CVE-2021-1463: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacke
nvd
CVE-2021-1395P4MEDIUMCVSS 6.1≤ 12.5\(1\)2021-06-16
CVE-2021-1395 [MEDIUM] CWE-79 CVE-2021-1395: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could
nvd
CVE-2023-20058P4MEDIUMCVSS 6.1fixed in 12.5\(1\)_su2_es05≥ 12.5\(1\)_su2, < 12.5\(1\)_su2_es052023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
nvd
CVE-2023-20096P4MEDIUMCVSS 5.4fixed in 12.5\(1\)su32023-04-05
CVE-2023-20096 [MEDIUM] CWE-79 CVE-2023-20096: A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unifi A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by entering craf
nvd
CVE-2018-0400P4MEDIUMCVSS 6.1v11.5\(1\)2018-07-18
CVE-2018-0400 [MEDIUM] CWE-79 CVE-2018-0400: Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Expre Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
nvd
CVE-2018-0401P4MEDIUMCVSS 6.1v11.5\(1\)2018-07-18
CVE-2018-0401 [MEDIUM] CWE-79 CVE-2018-0401: Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Expre Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70967.
nvd
CVE-2025-20114P4MEDIUMCVSS 4.3v8.5\(1\)v9.0\(2\)su3es04+58 more2025-05-21
CVE-2025-20114 [MEDIUM] CWE-639 CVE-2025-20114: A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted
nvd
Cisco Unified Contact Center Express vulnerabilities | cvebase