cbcvebase.

Cisco Unified Intelligence Center vulnerabilities

25 known vulnerabilities affecting cisco/unified_intelligence_center.

Total CVEs
25
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH8MEDIUM16

Vulnerabilities

Page 2 of 2
CVE-2021-1395P4MEDIUMCVSS 6.1≤ 12.0\(1\)v12.5\(1\)2021-06-16
CVE-2021-1395 [MEDIUM] CWE-79 CVE-2021-1395: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could
nvd
CVE-2023-20058P4MEDIUMCVSS 6.1fixed in 12.5\(1\)_es02≥ 12.6\(1\), < 12.6\(1\)_es06+1 more2023-01-20
CVE-2023-20058 [MEDIUM] CWE-79 CVE-2023-20058: A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could all A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An att
nvd
CVE-2025-20114P4MEDIUMCVSS 4.3v10.5\(1\)v11.0\(1\)+11 more2025-05-21
CVE-2025-20114 [MEDIUM] CWE-639 CVE-2025-20114: A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote A vulnerability in the API of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to perform a horizontal privilege escalation attack on an affected system. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by submitting crafted
nvd
CVE-2016-6425P4MEDIUMCVSS 6.1v8.5.4v9.0\(2\)+1 more2016-10-06
CVE-2016-6425 [MEDIUM] CWE-79 CVE-2016-6425: Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9 Cross-site scripting (XSS) vulnerability in Cisco Unified Intelligence Center (CUIC) 8.5.4 through 9.1(1), as used in Unified Contact Center Express 10.0(1) through 11.0(1), allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCuy75020 and CSCuy81652.
nvd
CVE-2023-20062P4MEDIUMCVSS 4.3fixed in 12.6\(2\)2023-03-03
CVE-2023-20062 [MEDIUM] CWE-200 CVE-2023-20062: Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote a Multiple vulnerabilities in Cisco Unified Intelligence Center could allow an authenticated, remote attacker to collect sensitive information or perform a server-side request forgery (SSRF) attack on an affected system. Cisco plans to release software updates that address these vulnerabilities.
nvd
Cisco Unified Intelligence Center vulnerabilities | cvebase