cbcvebase.

Cisco Unified Intelligence Center vulnerabilities

25 known vulnerabilities affecting cisco/unified_intelligence_center.

Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH8MEDIUM16

Vulnerabilities

Page 1 of 2
CVE-2021-44228P1CRITICALCVSS 10.0KEVPoCRansomwarefixed in 12.6\(1\)v12.6\(1\)+1 more2021-12-10
CVE-2021-44228 [CRITICAL] CWE-20 CVE-2021-44228: Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LD
nvd
CVE-2025-20274P2HIGHCVSS 8.8v10.5\(1\)v11.0\(1\)+11 more2025-07-16
CVE-2025-20274 [HIGH] CWE-434 CVE-2025-20274: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to improper validation of files that are uploaded to the web-based management interface. An attacker could exploit this vulnerability by upl
nvd
CVE-2017-12253P3HIGHCVSS 8.8v11.5\(1\)2017-09-21
CVE-2017-12253 [HIGH] CWE-352 CVE-2017-12253: A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote atta A vulnerability in the Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to execute unwanted actions. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker could exploit this vulnerability by tricking the user of a web application into executing an adverse action. Cisco Bug IDs:
nvd
CVE-2025-20113P3HIGHCVSS 7.1v10.5\(1\)v11.0\(1\)+11 more2025-05-21
CVE-2025-20113 [HIGH] CWE-602 CVE-2025-20113: A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker t A vulnerability in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to elevate privileges to Administrator for a limited set of functions on an affected system. This vulnerability is due to insufficient server-side validation of user-supplied parameters in API or HTTP requests. An attacker could exploit this vulnerabili
nvd
CVE-2017-6779P3HIGHCVSS 7.5≥ 11.6, < 11.6\(1\)v9.5\(1\)2018-06-07
CVE-2017-6779 [HIGH] CWE-399 CVE-2017-6779: Multiple Cisco products are affected by a vulnerability in local file management for certain system Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaboration products that could allow an unauthenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability occurs because a certain system log file does not have a maxi
nvd
CVE-2016-6426P3HIGHCVSS 7.5v8.5.4v9.0\(2\)+1 more2016-10-05
CVE-2016-6426 [HIGH] CWE-20 CVE-2016-6426: The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through The j_spring_security_switch_user function in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to create user accounts by visiting an unspecified web page, aka Bug IDs CSCuy75027 and CSCuy81653.
nvd
CVE-2019-1658P3HIGHCVSS 7.4v11.6\(1\)2019-01-24
CVE-2019-1658 [HIGH] CWE-352 CVE-2019-1658: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protections in the web-based management interface. An attacker
nvd
CVE-2016-6427P3HIGHCVSS 8.8v8.5.4v9.0\(2\)+1 more2016-10-06
CVE-2016-6427 [HIGH] CWE-352 CVE-2016-6427: Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 th Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuy75036 and CSCuy81654.
nvd
CVE-2023-20061P3MEDIUMCVSS 6.5fixed in 12.6\(2\)2023-03-03
CVE-2023-20061 [MEDIUM] CWE-200 CVE-2023-20061: Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote a Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
nvd
CVE-2025-20278P3MEDIUMCVSS 6.7fixed in 12.6\(2\)es_042025-06-04
CVE-2025-20278 [MEDIUM] CWE-77 CVE-2025-20278: A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenti A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerab
nvd
CVE-2024-20325P3HIGHCVSS 7.1fixed in 12.5(1)_es03≥ 12.6(1), < 12.6(1)_es08+1 more2024-02-21
CVE-2024-20325 [HIGH] CWE-284 CVE-2024-20325: A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthen A vulnerability in the Live Data server of Cisco Unified Intelligence Center could allow an unauthenticated, local attacker to read and modify data in a repository that belongs to an internal service on an affected device. This vulnerability is due to insufficient access control implementations on cluster configuration CLI requests. An attacker could
nvd
CVE-2025-20288P3MEDIUMCVSS 5.3v10.5\(1\)v11.0\(1\)+11 more2025-07-16
CVE-2025-20288 [MEDIUM] CWE-918 CVE-2025-20288: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability
nvd
CVE-2017-12254P4MEDIUMCVSS 6.1v11.5\(1\)2017-09-21
CVE-2017-12254 [MEDIUM] CWE-79 CVE-2017-12254: A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthentic A vulnerability in the web interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to perform a Document Object Model (DOM)-based cross-site scripting attack. The vulnerability is due to insufficient input validation of some parameters passed to the web server. An attacker could exploit this vulnerability by con
nvd
CVE-2017-12248P4MEDIUMCVSS 6.1v11.5\(1\)2017-09-21
CVE-2017-12248 [MEDIUM] CWE-79 CVE-2017-12248: A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow A vulnerability in the web framework code of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of some parameters that are passed to the web server
nvd
CVE-2019-1860P4MEDIUMCVSS 5.9v12.0\(1\)2019-05-16
CVE-2019-1860 [MEDIUM] CWE-99 CVE-2019-1860: A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow a A vulnerability in the dashboard gadget rendering of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to obtain or manipulate sensitive information between a user’s browser and Cisco Unified Intelligence Center. The vulnerability is due to the lack of gadget validation. An attacker could exploit this vulnerability by fo
nvd
CVE-2017-6789P4MEDIUMCVSS 6.1v11.0\(1\)es102017-09-07
CVE-2017-6789 [MEDIUM] CWE-79 CVE-2017-6789: A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticate A vulnerability in the Cisco Unified Intelligence Center web interface could allow an unauthenticated, remote attacker to impact the integrity of the system by executing a Document Object Model (DOM)-based, environment or client-side cross-site scripting (XSS) attack. The vulnerability occurs because user-supplied data in the DOM input is not validated
nvd
CVE-2019-1670P4MEDIUMCVSS 6.1v9.5\(1\)2019-02-07
CVE-2019-1670 [MEDIUM] CWE-79 CVE-2019-1670: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of a user-supplied value. An attacker could
nvd
CVE-2015-0740P4MEDIUMCVSS 6.8v10.6\(1\)2015-05-20
CVE-2015-0740 [MEDIUM] CWE-352 CVE-2015-0740: Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1) allows Cross-site request forgery (CSRF) vulnerability in Cisco Unified Intelligence Center 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCus28826.
nvd
CVE-2015-4274P4MEDIUMCVSS 6.8v10.0\(1\)v10.6\(1\)2015-07-16
CVE-2015-4274 [MEDIUM] CWE-352 CVE-2015-4274: Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence C Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified Intelligence Center 10.0(1) and 10.6(1) allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCuu94862 and CSCuu97936.
nvd
CVE-2021-1463P4MEDIUMCVSS 6.1≤ 11.6\(1\)≥ 12.0\(1\), < 12.0\(1\)es14+1 more2021-04-08
CVE-2021-1463 [MEDIUM] CWE-79 CVE-2021-1463: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software A vulnerability in the web-based management interface of Cisco Unified Intelligence Center Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacke
nvd
Cisco Unified Intelligence Center vulnerabilities | cvebase