cbcvebase.

Cisco Unity Connection vulnerabilities

60 known vulnerabilities affecting cisco/unity_connection.

Total CVEs
60
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH15MEDIUM39

Vulnerabilities

Page 2 of 3
CVE-2020-3130P3MEDIUMCVSS 6.5≥ 11.0, < 11.5su7≥ 12.0, < 12.5su22020-09-23
CVE-2020-3130 [MEDIUM] CWE-22 CVE-2020-3130: A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticat A vulnerability in the web management interface of Cisco Unity Connection could allow an authenticated remote attacker to overwrite files on the underlying filesystem. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web management interface. A successful ex
nvd
CVE-2021-1226P3MEDIUMCVSS 6.5≥ 11.5\(1\), < 11.5\(1\)su9≥ 12.0\(1\), < 12.0\(1\)su4+2 more2021-01-13
CVE-2021-1226 [MEDIUM] CWE-532 CVE-2021-1226: A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unifie A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, Cisco Emergency Responder, and Cisco Prime License Manager could allow an authenticated, remote attacker to view sen
nvd
CVE-2025-20278P3MEDIUMCVSS 6.7v12.5\(1\)v12.5\(1\)su1+9 more2025-06-04
CVE-2025-20278 [MEDIUM] CWE-77 CVE-2025-20278: A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenti A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the root user. This vulnerability is due to improper validation of user-supplied command arguments. An attacker could exploit this vulnerab
nvd
CVE-2012-0367P3HIGHCVSS 7.8≤ 7.1\(5b\)su4v1.1+61 more2012-03-01
CVE-2012-0367 [HIGH] CWE-399 CVE-2012-0367: Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allow Cisco Unity Connection before 7.1.5b(Su5), 8.0 and 8.5 before 8.5.1(Su3), and 8.6 before 8.6.2 allows remote attackers to cause a denial of service (services crash) via a series of crafted TCP segments, aka Bug ID CSCtq67899.
nvd
CVE-2019-1915P4MEDIUMCVSS 6.5v11.5v12.0+2 more2019-10-02
CVE-2019-1915 [MEDIUM] CWE-352 CVE-2019-1915: A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Co A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CS
nvd
CVE-2017-6629P4MEDIUMCVSS 5.3v10.5\(2\)2017-05-03
CVE-2017-6629 [MEDIUM] CWE-22 CVE-2017-6629: A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenti A vulnerability in the ImageID parameter of Cisco Unity Connection 10.5(2) could allow an unauthenticated, remote attacker to access files in arbitrary locations on the filesystem of an affected device. The issue is due to improper sanitization of user-supplied input in HTTP POST parameters that describe filenames. An attacker could exploit this vulner
nvd
CVE-2012-3060P4HIGHCVSS 7.8v8.6v9.0+1 more2012-09-16
CVE-2012-3060 [HIGH] CWE-399 CVE-2012-3060: Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service ( Cisco Unity Connection (UC) 8.6, 9.0, and 9.5 allows remote attackers to cause a denial of service (CPU consumption) via malformed UDP packets, aka Bug ID CSCtz76269.
nvd
CVE-2015-0612P4HIGHCVSS 7.1v8.5\(1\)v8.5\(1\)su1+14 more2015-04-03
CVE-2015-0612 [HIGH] CWE-19 CVE-2015-0612: The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1 The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU6, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (SIP outage) via a crafted UDP packet, aka Bug ID CSCuh25062.
nvd
CVE-2015-0616P4HIGHCVSS 7.1v8.5\(1\)v8.5\(1\)su1+17 more2015-04-03
CVE-2015-0616 [HIGH] CWE-19 CVE-2015-0616: The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1 The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, and 9.x before 9.1(2)SU2, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) by improperly terminating SIP TCP connections, aka Bug ID CSCul69819.
nvd
CVE-2018-15396P4MEDIUMCVSS 6.8v12.52018-10-05
CVE-2018-15396 [MEDIUM] CWE-399 CVE-2018-15396: A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an auth A vulnerability in the Bulk Administration Tool (BAT) for Cisco Unity Connection could allow an authenticated, remote attacker to cause high disk utilization, resulting in a denial of service (DoS) condition. The vulnerability exists because the affected software does not restrict the maximum size of certain files that can be written to disk. An att
nvd
CVE-2015-0614P4HIGHCVSS 7.1v8.5\(1\)v8.5\(1\)su1+19 more2015-04-03
CVE-2015-0614 [HIGH] CWE-19 CVE-2015-0614: The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1 The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.
nvd
CVE-2015-0613P4HIGHCVSS 7.1v8.5\(1\)v8.5\(1\)su1+19 more2015-04-03
CVE-2015-0613 [HIGH] CWE-19 CVE-2015-0613: The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1 The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul20444.
nvd
CVE-2022-20752P4MEDIUMCVSS 5.3≥ 12.5\(1\), < 12.5\(1\)su6≥ 14.0, < 14su12022-07-06
CVE-2022-20752 [MEDIUM] CWE-208 CVE-2022-20752: A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications M A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to perform a timing attack. This vulnerability is due to insufficient protection of a system password. An attacker could exp
nvd
CVE-2015-0615P4HIGHCVSS 7.1v8.5\(1\)v8.5\(1\)su1+19 more2015-04-03
CVE-2015-0615 [HIGH] CWE-19 CVE-2015-0615: The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)S The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (port consumption) by improperly terminating SIP sessions, aka Bug ID CSCul28089.
nvd
CVE-2018-0354P4MEDIUMCVSS 6.1v12.52018-06-07
CVE-2018-0354 [MEDIUM] CWE-79 CVE-2018-0354: A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remot A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via the HTTP G
nvd
CVE-2026-20059P4MEDIUMCVSS 6.1≤ 12.5v14.0+10 more2026-04-15
CVE-2026-20059 [MEDIUM] CWE-79 CVE-2026-20059: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unaut A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerab
nvd
CVE-2019-1685P4MEDIUMCVSS 6.1v12.52019-02-21
CVE-2019-1685 [MEDIUM] CWE-79 CVE-2019-1685: A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of C A vulnerability in the Security Assertion Markup Language (SAML) single sign-on (SSO) interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the
nvd
CVE-2017-12212P4MEDIUMCVSS 6.1v10.5\(2\)2017-09-07
CVE-2017-12212 [MEDIUM] CWE-79 CVE-2017-12212: A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remot A vulnerability in the web framework of Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insufficient input validation of certain parameters that are passed to the affected software via
nvd
CVE-2021-1409P4MEDIUMCVSS 6.1fixed in 14.02021-04-08
CVE-2021-1409 [MEDIUM] CWE-89 CVE-2021-1409: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd
CVE-2021-1380P4MEDIUMCVSS 6.1fixed in 14.02021-04-08
CVE-2021-1380 [MEDIUM] CWE-89 CVE-2021-1380: Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manag Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to
nvd