Home/Product/cisco unified communications manager
Product

cisco unified communications manager

238 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-20045
>= 12.5 and < 14su5
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edit
8.2HIGH
CVE-2025-20326
>= 15.0 and < 15su3
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unif
4.3MEDIUM
CVE-2025-20309
all versions
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management E
10.0CRITICAL
CVE-2025-20278
all versions
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execu
6.0MEDIUM
CVE-2020-3420
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
5.4MEDIUM
CVE-2024-20511
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
6.1MEDIUM
CVE-2024-20488
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
6.1MEDIUM
CVE-2024-20375
all versions
A vulnerability in the SIP call processing function of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communi
8.6HIGH
CVE-2024-20253
>= 14.0 and < 14su3
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, rem
9.9CRITICAL
CVE-2023-20259
all versions
A vulnerability in an API endpoint of multiple Cisco Unified Communications Products could allow an unauthenticated, remote attack
8.6HIGH
CVE-2023-20266
all versions
A vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Mana
6.5MEDIUM
CVE-2023-20211
>= 12.5\(1\) and < 12.5\(1\)sub
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
8.1HIGH
CVE-2023-20242
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Sessi
4.8MEDIUM
CVE-2023-20116
all versions
A vulnerability in the Administrative XML Web Service (AXL) API of Cisco Unified Communications Manager (Unified CM) and Cisco Uni
6.8MEDIUM
CVE-2023-20010
>= 11.5\(1\) and < 12.5\(1\)su7
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
8.1HIGH
CVE-2022-20816
>= 11.5\(1\) and < 14su2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
6.5MEDIUM
CVE-2022-20862
>= 14.0 and < 14su2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
4.3MEDIUM
CVE-2022-20859
>= 14.0 and < 14su2
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communicati
6.5MEDIUM
CVE-2022-20815
>= 14.0 and < 14su2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Sessi
6.1MEDIUM
CVE-2022-20800
>= 11.5\(1\) and < 14su2
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communic
6.1MEDIUM
CVE-2022-20791
<= 11.5\(1.10000.6\)
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications
6.5MEDIUM
CVE-2022-20752
>= 12.5\(1\) and < 12.5\(1\)su6
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edit
5.3MEDIUM
CVE-2022-20804
<= 14.0
A vulnerability in the Cisco Discovery Protocol of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communicati
5.3MEDIUM
CVE-2022-20790
<= 14.0
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Commu
6.5MEDIUM
CVE-2022-20789
all versions
A vulnerability in the software upgrade process of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communicati
4.9MEDIUM
CVE-2022-20788
>= 11.5\(1\) and < 11.5\(1\)su11
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Sessi
6.1MEDIUM
CVE-2022-20787
>= 12.5\(1\) and < 12.5\(1\)su6
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) Software and Cisco Unif
5.7MEDIUM
CVE-2021-44228
< 11.5\(1\)
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration
10.0CRITICAL
CVE-2021-34773
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communic
6.5MEDIUM
CVE-2021-34701
< 14su1
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communic
4.3MEDIUM
CVE-2021-1478
< 12.6
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco U
5.3MEDIUM
CVE-2021-1409
< 14
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified
6.1MEDIUM
CVE-2021-1408
< 14
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified
6.1MEDIUM
CVE-2021-1407
< 14
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified
6.1MEDIUM
CVE-2021-1406
all versions
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management E
4.9MEDIUM
CVE-2021-1399
>= 10.5\(2\) and < 12.5\(1\)su4
A vulnerability in the Self Care Portal of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Mana
4.3MEDIUM
CVE-2021-1380
< 14
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified
6.1MEDIUM
CVE-2021-1362
>= 10.5\(2\) and < 11.5\(1\)su9
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Man
8.8HIGH
CVE-2021-1364
< 11.5\(1\)su9
Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an at
6.5MEDIUM
CVE-2021-1357
< 11.5\(1\)su9
Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an at
6.5MEDIUM
CVE-2021-1355
< 11.5\(1\)su9
Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an at
6.5MEDIUM
CVE-2021-1282
< 11.5\(1\)su9
Multiple vulnerabilities in Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P) could allow an at
6.5MEDIUM
CVE-2021-1226
>= 11.5\(1\) and < 11.5\(1\)su9
A vulnerability in the audit logging component of Cisco Unified Communications Manager, Cisco Unified Communications Manager Sessi
4.3MEDIUM
CVE-2020-3135
< 11.5\(1\)
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (UCM) could allow an unauthenticated
8.8HIGH
CVE-2019-15963
>= 10.5 and <= 10.5\(2.10000.5\)
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote
6.5MEDIUM
CVE-2020-3346
>= 10.5\(2\) and <= 10.5\(2\)su10
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Sessio
6.1MEDIUM
CVE-2020-3282
>= 10.5\(2\) and < 10.5\(2\)su10
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manage
6.1MEDIUM
CVE-2020-3177
all versions
A vulnerability in the Tool for Auto-Registered Phones Support (TAPS) of Cisco Unified Communications Manager (UCM) and Cisco Unif
7.5HIGH
CVE-2015-0749
<= 10.5\(2.10000.5\)
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site sc
4.3MEDIUM
CVE-2019-15972
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote
8.8HIGH
CVE-2019-1915
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session M
6.5MEDIUM
CVE-2019-15272
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Sessio
6.5MEDIUM
CVE-2019-12716
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Sessio
6.1MEDIUM
CVE-2019-12715
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Sessio
6.1MEDIUM
CVE-2019-12711
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Sessio
6.5MEDIUM
CVE-2019-12710
all versions
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Sessio
4.9MEDIUM
CVE-2019-12707
all versions
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remot
6.1MEDIUM
CVE-2019-1887
all versions
A vulnerability in the Session Initiation Protocol (SIP) protocol implementation of Cisco Unified Communications Manager could all
8.6HIGH
CVE-2019-1837
all versions
A vulnerability in the User Data Services (UDS) API of Cisco Unified Communications Manager (Unified CM) could allow an unauthenti
5.3MEDIUM
CVE-2018-0474
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote
8.8HIGH
CVE-2018-15403
all versions
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communicati
5.4MEDIUM
CVE-2018-0411
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remo
6.1MEDIUM
CVE-2018-0355
all versions
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an unauthenticated, remote attacker
6.1MEDIUM
CVE-2018-0340
all versions
A vulnerability in the web framework of the Cisco Unified Communications Manager (Unified CM) software could allow an authenticate
5.4MEDIUM
CVE-2017-6779
>= 10.0 and < 10.5\(2\)su5
Multiple Cisco products are affected by a vulnerability in local file management for certain system log files of Cisco collaborati
7.5HIGH
CVE-2018-0328
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager and Cisco Unified Presence could allow an unauthentic
6.1MEDIUM
CVE-2018-0267
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, local attacker to view
6.5MEDIUM
CVE-2018-0266
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to view
4.3MEDIUM
CVE-2018-0198
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to vi
5.3MEDIUM
CVE-2018-0206
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remo
6.1MEDIUM
CVE-2018-0135
all versions
A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive informat
4.3MEDIUM
CVE-2018-0120
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to cond
4.3MEDIUM
CVE-2018-0105
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to vi
5.3MEDIUM
CVE-2018-0118
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remo
6.1MEDIUM
CVE-2017-12357
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote
5.4MEDIUM
CVE-2017-12337
all versions
A vulnerability in the upgrade mechanism of Cisco collaboration products based on the Cisco Voice Operating System software platfo
9.8CRITICAL
CVE-2017-12258
all versions
A vulnerability in the web-based UI of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to exe
6.1MEDIUM
CVE-2017-6791
all versions
A vulnerability in the Trust Verification Service (TVS) of Cisco Unified Communications Manager could allow an unauthenticated, re
7.5HIGH
CVE-2017-6785
all versions
A vulnerability in configuration modification permissions validation for Cisco Unified Communications Manager could allow an authe
4.3MEDIUM
CVE-2017-6758
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote
6.5MEDIUM
CVE-2017-6757
all versions
A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an auth
8.8HIGH
CVE-2017-6654
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager 10.5 through 11.5 could allow an una
6.1MEDIUM
CVE-2017-3808
all versions
A vulnerability in the Session Initiation Protocol (SIP) UDP throttling process of Cisco Unified Communications Manager (Cisco Uni
7.5HIGH
CVE-2017-3888
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote
5.4MEDIUM
CVE-2017-3886
all versions
A vulnerability in the Cisco Unified Communications Manager web interface could allow an authenticated, remote attacker to impact
4.9MEDIUM
CVE-2017-3877
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an unauthenticated, remote
6.5MEDIUM
CVE-2017-3874
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager (CallManager) could allow an authenticated, remote at
5.4MEDIUM
CVE-2017-3872
all versions
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Man
6.1MEDIUM
CVE-2017-3836
all versions
A vulnerability in the web framework Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to view
4.3MEDIUM
CVE-2017-3833
all versions
A vulnerability in the web framework of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to co
6.1MEDIUM
CVE-2017-3829
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthentica
6.1MEDIUM
CVE-2017-3828
all versions
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthentica
6.1MEDIUM
CVE-2017-3821
all versions
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker
6.1MEDIUM
CVE-2017-3802
all versions
A vulnerability in Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct a cross-site sc
6.1MEDIUM
CVE-2017-3798
all versions
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Man
6.1MEDIUM
CVE-2016-9210
all versions
A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an un
7.5HIGH
CVE-2016-9206
all versions
A vulnerability in the ccmadmin page of Cisco Unified Communications Manager (CUCM) could allow an unauthenticated, remote attacke
6.1MEDIUM
CVE-2016-6472
all versions
A vulnerability in several parameters of the ccmivr page of Cisco Unified Communication Manager (CallManager) could allow an unaut
6.1MEDIUM
CVE-2016-6440
all versions
The Cisco Unified Communications Manager (CUCM) may be vulnerable to data that can be displayed inside an iframe within a web page
6.5MEDIUM
CVE-2016-6364
all versions
The User Data Services (UDS) API implementation in Cisco Unified Communications Manager 11.5 allows remote attackers to bypass int
7.5HIGH
CVE-2015-6360
all versions
The encryption-processing feature in Cisco libSRTP before 1.5.3 allows remote attackers to cause a denial of service via crafted f
7.5HIGH
CVE-2015-6433
all versions
SQL injection vulnerability in Cisco Unified Communications Manager 11.0(0.98000.225) allows remote authenticated users to execute
6.5MEDIUM
CVE-2015-6425
all versions
The WebApplications Identity Management subsystem in Cisco Unified Communications Manager 10.5(0.98000.88) allows remote attackers
CVE-2015-4206
all versions
Cisco Unified Communications Manager (UCM) 8.0 through 8.6 allows remote attackers to bypass an XSS protection mechanism via a cra
CVE-2015-4295
all versions
The Prime Collaboration Deployment component in Cisco Unified Communications Manager 10.5(3.10000.9) allows remote authenticated u
CVE-2015-4272
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the ccmivr page in Cisco Unified Communications Manager (formerly CallManag
CVE-2015-4269
all versions
The Tomcat throttling feature in Cisco Unified Communications Manager 10.5(1.99995.9) allows remote authenticated users to cause a
CVE-2015-0751
all versions
Cisco IP Phone 7861, when firmware from Cisco Unified Communications Manager 10.3(1) is used, allows remote attackers to cause a d
CVE-2015-0717
all versions
Cisco Unified Communications Manager 10.0(1.10000.12) allows local users to gain privileges via a command string in an unspecified
CVE-2014-8008
all versions
Absolute path traversal vulnerability in the Real-Time Monitoring Tool (RTMT) API in Cisco Unified Communications Manager (CUCM) a
CVE-2014-7991
<= 10.0\(1\)
The Remote Mobile Access Subsystem in Cisco Unified Communications Manager (CM) 10.0(1) and earlier does not properly validate the
CVE-2014-3375
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Service interface in the Server in Cisco Unified Communications Man
CVE-2014-3374
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the CCM admin interface in the Server in Cisco Unified Communications Manag
CVE-2014-3373
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the CCM Dialed Number Analyzer interface in the Server in Cisco Unified Com
CVE-2014-3372
all versions
Multiple cross-site scripting (XSS) vulnerabilities in the CCM reports interface in the Server in Cisco Unified Communications Man
CVE-2014-3366
all versions
SQL injection vulnerability in the administrative web interface in Cisco Unified Communications Manager allows remote authenticate
CVE-2014-3363
all versions
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Unified Communications Manager (UCM) 9.1(2.10000.28) allows
CVE-2014-3338
all versions
The CTIManager module in Cisco Unified Communications Manager (CM) 10.0(1), when single sign-on is enabled, does not properly vali
CVE-2014-3332
<= 8.6\(2\)
Cisco Unified Communications Manager (CM) 8.6(.2) and earlier has an incorrect CLI restrictions setting, which allows remote authe
CVE-2014-3319
all versions
Directory traversal vulnerability in the Real-Time Monitoring Tool (RTMT) in Cisco Unified Communications Manager (CM) 10.0(1) all
CVE-2014-3317
all versions
Directory traversal vulnerability in the Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communic
CVE-2014-3318
all versions
Directory traversal vulnerability in dna/viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Commun
CVE-2014-3316
all versions
The Multiple Analyzer in the Dialed Number Analyzer (DNA) component in Cisco Unified Communications Manager allows remote authenti
CVE-2014-3315
all versions
Cross-site scripting (XSS) vulnerability in viewfilecontents.do in the Dialed Number Analyzer (DNA) component in Cisco Unified Com
CVE-2014-3292
all versions
The Real Time Monitoring Tool (RTMT) implementation in Cisco Unified Communications Manager (Unified CM) allows remote authenticat
CVE-2014-3287
all versions
SQL injection vulnerability in BulkViewFileContentsAction.java in the Java interface in Cisco Unified Communications Manager (Unif
CVE-2014-2185
all versions
The Call Detail Records (CDR) Management component in Cisco Unified Communications Manager (Unified CM) allows remote authenticate
CVE-2014-2184
all versions
The IP Manager Assistant (IPMA) component in Cisco Unified Communications Manager (Unified CM) allows remote attackers to obtain s
CVE-2014-0747
<= 10.0\(1\)
The Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communications Manager (Unified CM) 10.0(1) an
CVE-2014-0743
<= 10.0\(1\)
The Certificate Authority Proxy Function (CAPF) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier
CVE-2014-0742
<= 10.0\(1\)
The Certificate Authority Proxy Function (CAPF) CLI implementation in the CSR management feature in Cisco Unified Communications M
CVE-2014-0741
<= 10.0\(1\)
The certificate-import feature in the Certificate Authority Proxy Function (CAPF) CLI implementation in Cisco Unified Communicatio
CVE-2014-0740
<= 10.0\(1\)
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) interface in the OS Admini
CVE-2014-0731
<= 10.0\(1\)
The administration interface in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier allows remote attackers to b
CVE-2014-0733
<= 10.0\(1\)
The Enterprise License Manager (ELM) component in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does not p
CVE-2014-0736
<= 10.0\(1\)
Cross-site request forgery (CSRF) vulnerability in the Call Detail Records Analysis and Reporting (CAR) page in Cisco Unified Comm
CVE-2014-0735
<= 10.0\(1\)
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (Uni
CVE-2014-0734
<= 10.0\(1\)
SQL injection vulnerability in the Certificate Authority Proxy Function (CAPF) implementation in Cisco Unified Communications Mana
CVE-2014-0732
<= 10.0\(1\)
The Real Time Monitoring Tool (RTMT) web application in Cisco Unified Communications Manager (Unified CM) 10.0(1) and earlier does
CVE-2014-0729
all versions
SQL injection vulnerability in the Enterprise Mobility Application (EMApp) interface in Cisco Unified Communications Manager (UCM)
CVE-2014-0728
<= 10.0\(1\)
SQL injection vulnerability in the Java database interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allow
CVE-2014-0727
all versions
SQL injection vulnerability in the CallManager Interactive Voice Response (CMIVR) interface in Cisco Unified Communications Manage
CVE-2014-0726
<= 10.0\(1\)
SQL injection vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM) 10.0(1) and
CVE-2014-0725
all versions
Cisco Unified Communications Manager (UCM) does not require authentication for reading WAR files, which allows remote attackers to
CVE-2014-0724
<= 10.0\(1\)
The bulk administration interface in Cisco Unified Communications Manager (UCM) 10.0(1) and earlier allows remote attackers to byp
CVE-2014-0723
all versions
Cross-site scripting (XSS) vulnerability in the IP Manager Assistant (IPMA) interface in Cisco Unified Communications Manager (UCM
CVE-2014-0722
all versions
The log4jinit web application in Cisco Unified Communications Manager (UCM) does not properly validate authentication, which allow
CVE-2014-0686
<= 9.1\(2.10000.28\)
Cisco Unified Communications Manager (aka Unified CM) 9.1 (2.10000.28) and earlier allows local users to gain privileges by levera
CVE-2014-0657
<= 9.1\(1\)
The administration portal in Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier does not properly handle role re
CVE-2013-6978
<= 9.1\(1\)
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authen
CVE-2013-7030
all versions
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive info
7.3HIGH
CVE-2013-6689
<= 9.1\(1\)
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modi
CVE-2013-6688
<= 9.1\(1\)
Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unifi
CVE-2013-5555
all versions
Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restar
CVE-2013-5528
all versions
Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote
CVE-2013-3472
all versions
Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (C
CVE-2013-3462
all versions
Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) bef
CVE-2013-3461
all versions
Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly rest
CVE-2013-3460
all versions
Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before
CVE-2013-3459
all versions
Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote a
CVE-2013-3453
<= 8.6\(4\)
Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unif
CVE-2013-3451
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Unified Communications Manager (Unified CM) allow remote attac
CVE-2013-3450
all versions
Cross-site request forgery (CSRF) vulnerability in the User WebDialer page in Cisco Unified Communications Manager (Unified CM) al
CVE-2013-3442
all versions
The web portal in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive stack-tr
CVE-2013-4869
>= 7.1\(1\) and <= 9.1\(2\)
Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server t
CVE-2013-3434
all versions
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to ga
CVE-2013-3433
all versions
Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to ga
CVE-2013-3412
all versions
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users
CVE-2013-3404
all versions
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execu
CVE-2013-3403
all versions
Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local u
CVE-2013-3402
all versions
An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to
CVE-2013-3397
all versions
Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (C
CVE-2013-1188
all versions
Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attac
CVE-2013-1240
all versions
The command-line interface in Cisco Unified Communications Manager (CUCM) does not properly validate input, which allows local use
CVE-2013-1134
all versions
The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before
CVE-2013-1133
all versions
Cisco Unified Communications Manager (CUCM) 8.6 before 8.6(2a)su2, 8.6 BE3k before 8.6(4) BE3k, and 9.x before 9.0(1) allows remot
CVE-2012-3949
all versions
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6
CVE-2012-0376
all versions
The voice-sipstack component in Cisco Unified Communications Manager (CUCM) 8.5 allows remote attackers to cause a denial of servi
CVE-2011-4019
all versions
Memory leak in Cisco IOS 12.4 and 15.0 through 15.2, and Cisco Unified Communications Manager (CUCM) 7.x, allows remote attackers
CVE-2011-4487
all versions
SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before
CVE-2011-4486
all versions
Cisco Unified Communications Manager (CUCM) with software 6.x and 7.x before 7.1(5b)su5, 8.0 before 8.0(3a)su3, and 8.5 and 8.6 be
CVE-2011-0941
all versions
Memory leak in Cisco Unified Communications Manager (CUCM) 6.x before 6.1(5)su2, 7.x before 7.1(5b)su3, 8.x before 8.0(3a)su1, and
CVE-2011-3315
all versions
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x before 7.1(5b)S
CVE-2011-2072
all versions
Memory leak in Cisco IOS 12.4, 15.0, and 15.1, Cisco IOS XE 2.5.x through 3.2.x, and Cisco Unified Communications Manager (CUCM) 6
CVE-2011-2564
all versions
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly
CVE-2011-2563
all versions
Unspecified vulnerability in the Service Advertisement Framework (SAF) in Cisco Unified Communications Manager (aka CUCM, formerly
CVE-2011-2562
all versions
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x befor
CVE-2011-2561
all versions
The SIP process in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(5b)su4 and 8.x before 8.0(
CVE-2011-2560
all versions
The Packet Capture Service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x does not properly handle i
CVE-2011-1643
all versions
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x, 7.x before 7.1(5b)su4, 8.0, and 8.5 before 8.5(1)su2 an
CVE-2011-1610
all versions
Multiple SQL injection vulnerabilities in xmldirectorylist.jsp in the embedded Apache HTTP Server component in Cisco Unified Commu
CVE-2011-1609
all versions
SQL injection vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x bef
CVE-2011-1607
all versions
Directory traversal vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7
CVE-2011-1606
all versions
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x befor
CVE-2011-1605
all versions
Unspecified vulnerability in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su2, 7.x befor
CVE-2011-1604
all versions
Memory leak in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5)su3, 7.x before 7.1(5b)su3,
CVE-2010-3039
all versions
/usr/local/cm/bin/pktCap_protectData in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6, 7, and 8 allows r
CVE-2010-2835
all versions
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Man
CVE-2010-2834
all versions
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Man
CVE-2010-2838
<= 7.0\(2a\)su2
The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.
CVE-2010-2837
<= 6.1\(5\)
The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1,
CVE-2010-0592
all versions
The CTI Manager service in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)sr1a, 6.x before
CVE-2010-0591
all versions
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3b)SU2, and 8.x before 8.0
CVE-2010-0590
all versions
The CMSIPUtility component in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.x before 7.1(3a)su1 and 8.x
CVE-2010-0588
all versions
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.x before 6.1(5), 7.x before 7.1(3a)su1, and 8.x before 8.0
CVE-2010-0587
all versions
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x before 4.3(2)SR2, 6.x before 6.1(5), 7.x before 7.1(3a)s
CVE-2009-2864
all versions
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)s
CVE-2009-2054
>= 4.0 and < 5.1\(3g\)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2
CVE-2009-2053
>= 5.0 and < 5.1\(3g\)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2
CVE-2009-2052
>= 5.0 and < 5.1\(3g\)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 4.x, 5.x before 5.1(3g), 6.x before 6.1(4), 7.0 before 7.0(2
CVE-2009-2051
>= 5.0 and < 5.1\(3g\)
Cisco IOS 12.2 through 12.4 and 15.0 through 15.1, Cisco IOS XE 2.5.x and 2.6.x before 2.6.1, and Cisco Unified Communications Man
CVE-2009-2050
< 6.1\(1\)
Cisco Unified Communications Manager (aka CUCM, formerly CallManager) before 6.1(1) allows remote attackers to cause a denial of s
CVE-2009-0632
all versions
The IP Phone Personal Address Book (PAB) Synchronizer feature in Cisco Unified Communications Manager (aka CUCM, formerly CallMana
CVE-2009-0057
all versions
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager 5.x before 5.1(3e) and 6.x before
CVE-2008-3801
all versions
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Commu
CVE-2008-3800
all versions
Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Cisco IOS 12.2 through 12.4 and Unified Commu
CVE-2008-2730
all versions
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3) and
CVE-2008-2062
>= 4.2 and < 4.2\(3\)sr4
The Real-Time Information Server (RIS) Data Collector service in Cisco Unified Communications Manager (CUCM) before 4.2(3)SR4, and
CVE-2008-2061
>= 5.0 and < 5.1\(3c\)
The Computer Telephony Integration (CTI) Manager service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3c) and 6.x
CVE-2008-1748
>= 4.1 and < 4.1\(3\)sr7
Cisco Unified Communications Manager 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, 4.3 before 4.3(2), 5.x before 5.1(3), and 6.x bef
CVE-2008-1747
>= 4.1 and < 4.1\(3\)sr6
Unspecified vulnerability in Cisco Unified Communications Manager 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before 4.3(2), 5
CVE-2008-1746
all versions
The SNMP Trap Agent service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR6, 4.2 before 4.2(3)SR3, 4.3 before
CVE-2008-1745
all versions
Cisco Unified Communications Manager (CUCM) 5.x before 5.1(2) and 6.x before 6.1(1) allows remote attackers to cause a denial of s
CVE-2008-1744
all versions
The Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 b
CVE-2008-1743
>= 5.0 and < 5.1\(3\)
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3)
CVE-2008-1742
all versions
Memory leak in the Certificate Trust List (CTL) Provider service in Cisco Unified Communications Manager (CUCM) 5.x before 5.1(3)
CVE-2008-1154
all versions
The Disaster Recovery Framework (DRF) master server in Cisco Unified Communications products, including Unified Communications Man
CVE-2008-0026
all versions
SQL injection vulnerability in Cisco Unified CallManager/Communications Manager (CUCM) 5.0/5.1 before 5.1(3a) and 6.0/6.1 before 6
CVE-2008-0027
all versions
Heap-based buffer overflow in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications
CVE-2007-5538
<= 5.1\(2\)
Buffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager)
CVE-2007-5537
<= 5.1\(2\)
Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote att
CVE-2007-4634
all versions
Multiple SQL injection vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr2b, 4.1 befor
CVE-2007-4633
all versions
Multiple cross-site scripting (XSS) vulnerabilities in Cisco CallManager and Unified Communications Manager (CUCM) before 3.3(5)sr
CVE-2007-4294
all versions
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM) 5.0, 5.1, and 6.0, and IOS 12.0 through 12.4, allows remo
CVE-2007-3776
all versions
Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS) allow remote attackers to obt
CVE-2007-3775
all versions
Unspecified vulnerability in Cisco Unified Communications Manager (CUCM, formerly CallManager) and Unified Presence Server (CUPS)
CVE-2006-5278
>= 4.3 and <= 4.3\(1\)
Integer overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Mana
CVE-2006-5277
>= 4.3 and <= 4.3\(1\)
Off-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (C
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin