Skip to main content

Vendor/product archive

cisco / unified_communications_manager CVEs

Beta · best-effort

238 CVEs tagged to cisco / unified_communications_manager11 Critical, 76 High, 149 Medium, 1 Low, 1 Unrated.

CVE-2013-7030

Published Dec 12, 2013

The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as dem…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6689

Published Nov 18, 2013

Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload"…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6688

Published Nov 18, 2013

Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allo…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5555

Published Nov 1, 2013

Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub543…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5528

Published Oct 11, 2013

Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3472

Published Aug 29, 2013

Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote attackers to hijack the authenti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3462

Published Aug 25, 2013

Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(2) allows remo…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3461

Published Aug 25, 2013

Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3460

Published Aug 25, 2013

Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3459

Published Aug 25, 2013

Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a denial of service (service di…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3450

Published Aug 5, 2013

Cross-site request forgery (CSRF) vulnerability in the User WebDialer page in Cisco Unified Communications Manager (Unified CM) allows remote attackers to hijack the authenticatio…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3451

Published Aug 5, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco Unified Communications Manager (Unified CM) allow remote attackers to hijack the authentication of arbitrary us…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3442

Published Aug 5, 2013

The web portal in Cisco Unified Communications Manager (Unified CM) allows remote authenticated users to obtain sensitive stack-trace information via unspecified vectors that trig…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4869

Published Jul 18, 2013

Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service in Cisco Unified Presence Server through 9.1(2) use the same CTI and database-encry…

CVSS 0.0 · Unrated
Vendor/product tagsBeta · best-effort

CVE-2013-3434

Published Jul 18, 2013

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-perm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3433

Published Jul 18, 2013

Untrusted search path vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows local users to gain privileges by leveraging unspecified file-perm…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3412

Published Jul 18, 2013

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary SQL commands via unspecifie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3404

Published Jul 18, 2013

SQL injection vulnerability in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allows remote attackers to execute arbitrary SQL commands via unspecified vectors…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3403

Published Jul 18, 2013

Multiple untrusted search path vulnerabilities in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(1a) allow local users to gain privileges by leveraging unspecified…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3402

Published Jul 18, 2013

An unspecified function in Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) allows remote authenticated users to execute arbitrary commands via unknown vectors, a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3397

Published Jun 26, 2013

Cross-site request forgery (CSRF) vulnerability in the Unified Serviceability component in Cisco Unified Communications Manager (CUCM) allows remote attackers to hijack the authen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1188

Published May 16, 2013

Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application sl…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1240

Published May 4, 2013

The command-line interface in Cisco Unified Communications Manager (CUCM) does not properly validate input, which allows local users to read arbitrary files via unspecified vector…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1134

Published Feb 27, 2013

The Location Bandwidth Manager (LBM) Intracluster-communication feature in Cisco Unified Communications Manager (CUCM) 9.x before 9.1(1) does not require authentication from the r…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort
Showing 151-175 of 238 CVEsPage 7 of 10