Cisco Unity Connection vulnerabilities
60 known vulnerabilities affecting cisco/unity_connection.
Total CVEs
60
CISA KEV
2
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL6HIGH15MEDIUM39
Vulnerabilities
Page 3 of 3
CVE-2022-20788P4MEDIUMCVSS 6.1≥ 12.5\(1\), < 12.5\(1\)su6≥ 14.0, < 14su12022-04-21
CVE-2022-20788 [MEDIUM] CWE-79 CVE-2022-20788: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists b
nvd
CVE-2022-20800P4MEDIUMCVSS 6.1≥ 11.5\(1\), < 14su22022-07-06
CVE-2022-20800 [MEDIUM] CWE-79 CVE-2022-20800: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduc
nvd
CVE-2015-6408P4MEDIUMCVSS 6.8v11.5\(0.98\)2015-12-12
CVE-2015-6408 [MEDIUM] CWE-352 CVE-2015-6408: Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote a
Cross-site request forgery (CSRF) vulnerability in Cisco Unity Connection 11.5(0.98) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCux24578.
nvd
CVE-2019-12707P4MEDIUMCVSS 6.1v11.5v12.0+1 more2019-10-02
CVE-2019-12707 [MEDIUM] CWE-79 CVE-2019-12707: A vulnerability in the web-based interface of multiple Cisco Unified Communications products could a
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input by the web-based inte
nvd
CVE-2020-3282P4MEDIUMCVSS 6.1≥ 10.5\(2\), < 10.5\(2\)su10≥ 11.5\(1\), < 11.5\(1\)su8+2 more2020-07-02
CVE-2020-3282 [MEDIUM] CWE-79 CVE-2020-3282: A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us
nvd
CVE-2018-15403P4MEDIUMCVSS 5.4v9.1\(1\)es232018-10-05
CVE-2018-15403 [MEDIUM] CWE-601 CVE-2018-15403: A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Mana
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an authenticated, remote attacker to redirect a user to a malicious web page. The vulnerability is due to improper input validation of the paramete
nvd
CVE-2021-34701P4MEDIUMCVSS 4.3fixed in 14su12021-11-04
CVE-2021-34701 [MEDIUM] CWE-22 CVE-2021-34701: A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unifi
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authenticated, remote attacker to access s
nvd
CVE-2015-0716P4MEDIUMCVSS 6.8v11.0\(0.98000.225\)v11.0\(0.98000.332\)2015-05-07
CVE-2015-0716 [MEDIUM] CWE-352 CVE-2015-0716: Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.
Cross-site request forgery (CSRF) vulnerability in the CUCReports page in Cisco Unity Connection 11.0(0.98000.225) and 11.0(0.98000.332) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCut33659.
nvd
CVE-2026-20060P4MEDIUMCVSS 4.7≤ 12.5v14.0+9 more2026-04-15
CVE-2026-20060 [MEDIUM] CWE-601 CVE-2026-20060: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unaut
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an unauthenticated, remote attacker to redirect a user to a malicious web page.
This vulnerability is due to improper input validation of HTTP request parameters. An attacker could exploit this vulnerability by persuading a user to click a crafted link. A su
nvd
CVE-2016-1377P4MEDIUMCVSS 6.1v10.0.0v10.0.5+4 more2016-04-12
CVE-2016-1377 [MEDIUM] CWE-79 CVE-2016-1377: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attack
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.
nvd
CVE-2016-1304P4MEDIUMCVSS 6.1v10.5\(2.3009\)2016-01-30
CVE-2016-1304 [MEDIUM] CWE-79 CVE-2016-1304: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attack
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug ID CSCux82596.
nvd
CVE-2016-1300P4MEDIUMCVSS 6.1v10.5\(2.3009\)2016-01-27
CVE-2016-1300 [MEDIUM] CWE-79 CVE-2016-1300: Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote a
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection (UC) 10.5(2.3009) allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCux82582.
nvd
CVE-2013-1129P4MEDIUMCVSS 5.0v9.0v9.1+2 more2013-02-19
CVE-2013-1129 [MEDIUM] CWE-399 CVE-2013-1129: Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memo
Memory leak in Cisco Unity Connection 9.x allows remote attackers to cause a denial of service (memory consumption and process crash) by sending many TCP requests, aka Bug ID CSCud59736.
nvd
CVE-2020-3129P4MEDIUMCVSS 4.8fixed in 12.5su22020-01-26
CVE-2020-3129 [MEDIUM] CWE-79 CVE-2020-3129: A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow
A vulnerability in the web-based management interface of Cisco Unity Connection Software could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack. The vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by providing crafted d
nvd
CVE-2018-15426P4MEDIUMCVSS 4.8vvmo-11.5\(1\)2018-10-05
CVE-2018-15426 [MEDIUM] CWE-79 CVE-2018-15426: A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, r
A vulnerability in the web-based interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based interface of the affected software. The vulnerability is due to insufficient validation of user-supplied input that is processed by the web-based inter
nvd
CVE-2024-20305P4MEDIUMCVSS 4.8fixed in 15.02024-01-26
CVE-2024-20305 [MEDIUM] CWE-79 CVE-2024-20305: A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authe
A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit thi
nvd
CVE-2015-6390P4MEDIUMCVSS 4.3v9.1\(1.10\)2015-12-03
CVE-2015-6390 [MEDIUM] CWE-79 CVE-2015-6390: Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1
Cross-site scripting (XSS) vulnerability in the management interface in Cisco Unity Connection 9.1(1.10) allows remote attackers to inject arbitrary web script or HTML via a crafted value in a URL, aka Bug ID CSCup92741.
nvd
CVE-2014-2125P4MEDIUMCVSS 4.3≤ 8.6v8.6+2 more2014-04-02
CVE-2014-2125 [MEDIUM] CWE-79 CVE-2014-2125: Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and e
Cross-site scripting (XSS) vulnerability in the Web Inbox in Cisco Unity Connection 8.6(2a)SU3 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui33028.
nvd
CVE-2014-7988P4MEDIUMCVSS 4.0≤ 10.52014-11-07
CVE-2014-7988 [MEDIUM] CWE-200 CVE-2014-7988: The Unified Messaging Service (UMS) in Cisco Unity Connection 10.5 and earlier allows remote authent
The Unified Messaging Service (UMS) in Cisco Unity Connection 10.5 and earlier allows remote authenticated users to obtain sensitive information by reading log files, aka Bug ID CSCur06493.
nvd
CVE-2012-3096P4MEDIUMCVSS 4.0v7.1v8.0+1 more2012-09-16
CVE-2012-3096 [MEDIUM] CVE-2012-3096: Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of
Cisco Unity Connection (UC) 7.1, 8.0, and 8.5 allows remote authenticated users to cause a denial of service (resource consumption and administration outage) via extended use of the product, aka Bug ID CSCtd79132.
nvd
← Previous3 / 3