Cisco
Cisco Unified Communications Domain Manager: vulnerabilidades y CVE
Cisco Unified Communications Domain Manager tiene 41 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-15968 | Media (5.4) | 0.63% | — | 26 nov 2019 | A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager (Unified CDM) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a… |
| CVE-2018-0386 | Media (6.1) | 1.8% | — | 15 ago 2018 | A vulnerability in Cisco Unified Communications Domain Manager Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on an affected system. The vulnerability is due to… |
| CVE-2018-0364 | Alta (8.8) | 0.71% | — | 21 jun 2018 | A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform… |
| CVE-2018-0124 | Crítica (9.8) | 5.1% | — | 22 feb 2018 | A vulnerability in Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to bypass security protections, gain elevated privileges, and execute arbitrary code. The vulnerability is… |
| CVE-2017-12302 | Media (4.3) | 1.1% | — | 16 nov 2017 | A vulnerability in the Cisco Unified Communications Manager SQL database interface could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries, aka SQL… |
| CVE-2017-6670 | Media (6.1) | 1.2% | — | 13 jun 2017 | A vulnerability in the web-based GUI of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect issue. More… |
| CVE-2017-6668 | Media (4.9) | 1.3% | — | 13 jun 2017 | Vulnerabilities in the web-based GUI of Cisco Unified Communications Domain Manager (CUCDM) could allow an authenticated, remote attacker to impact the confidentiality of the system by executing arbitrary SQL queries,… |
| CVE-2016-1354 | Media (6.1) | 0.77% | — | 3 mar 2016 | Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 8.x before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via crafted markup data, aka Bug ID… |
| CVE-2015-6422 | Media (4) | 1.9% | — | 14 dic 2015 | The self-service application in Cisco Unified Communications Domain Manager (CUCDM) 10.6(1) allows remote authenticated users to cause a denial of service (subapplication outage) via malformed requests, aka Bug ID… |
| CVE-2015-6352 | Media (4.3) | 1.8% | — | 30 oct 2015 | Cisco Unified Communications Domain Manager before 10.6(1) provides different error messages for pathname access attempts depending on whether the pathname exists, which allows remote attackers to map a filesystem via a… |
| CVE-2015-4196 | Media (5) | 1.9% | — | 4 jul 2015 | Platform Software before 4.4.5 in Cisco Unified Communications Domain Manager (CDM) 8.x has a hardcoded password for a privileged account, which allows remote attackers to obtain root access by leveraging knowledge of… |
| CVE-2015-4229 | Media (5) | 2.6% | — | 30 jun 2015 | The web framework in Cisco Unified Communications Domain Manager 8.1(4)ER1 allows remote attackers to obtain sensitive information by visiting a bvsmweb URL, aka Bug ID CSCuq22589. |
| CVE-2015-0699 | Media (5) | 1.9% | — | 15 abr 2015 | SQL injection vulnerability in the Interactive Voice Response (IVR) component in Cisco Unified Communications Manager (UCM) 10.5(1.98991.13) allows remote attackers to execute arbitrary SQL commands via unspecified… |
| CVE-2015-0684 | Media (6.5) | 1.4% | — | 3 abr 2015 | SQL injection vulnerability in the Image Management component in Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID… |
| CVE-2015-0683 | Media (4) | 1.3% | — | 3 abr 2015 | Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to obtain sensitive information via a file-inclusion attack, aka Bug ID CSCup94744. |
| CVE-2015-0682 | Media (6.5) | 2.1% | — | 3 abr 2015 | Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168. |
| CVE-2015-0591 | Media (5) | 2.0% | — | 15 ene 2015 | Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to cause a denial of service (daemon hang and GUI outage) via a flood of malformed TCP packets, aka Bug ID CSCur44177. |
| CVE-2015-0588 | Media (6.8) | 1.3% | — | 15 ene 2015 | Cross-site request forgery (CSRF) vulnerability in Cisco Unified Communications Domain Manager (UCDM) 10 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuo77055. |
| CVE-2014-8020 | Media (5) | 2.4% | — | 10 ene 2015 | Cisco Unified Communication Domain Manager Platform Software allows remote attackers to cause a denial of service (CPU consumption, and performance degradation or service outage) via a flood of malformed TCP packets and… |
| CVE-2014-8018 | Media (4.3) | 1.8% | — | 22 dic 2014 | Multiple cross-site scripting (XSS) vulnerabilities in Business Voice Services Manager (BVSM) pages in the Application Software in Cisco Unified Communications Domain Manager 8 allow remote attackers to inject arbitrary… |
| CVE-2014-8010 | Media (6.5) | 1.5% | — | 10 dic 2014 | The web framework in Cisco Unified Communications Domain Manager 8 allows remote authenticated administrators to execute arbitrary OS commands via crafted values, aka Bug ID CSCuq50205. |
| CVE-2014-3339 | Media (6.5) | 1.5% | — | 12 ago 2014 | Multiple SQL injection vulnerabilities in the administrative web interface in Cisco Unified Communications Manager (CM) and Cisco Unified Presence Server (CUPS) allow remote authenticated users to execute arbitrary SQL… |
| CVE-2014-3337 | Media (6.8) | 2.4% | — | 12 ago 2014 | The SIP implementation in Cisco Unified Communications Manager (CM) 8.6(.2) and earlier allows remote authenticated users to cause a denial of service (process crash) via a crafted SIP message that is not properly… |
| CVE-2014-3320 | Media (5.8) | 2.2% | — | 18 jul 2014 | Multiple open redirect vulnerabilities in the admin web interface in the web framework in Cisco Unified Communications Domain Manager (CDM) 8.1(.4) and earlier allow remote attackers to redirect users to arbitrary web… |
| CVE-2014-3300 | Alta (7.5) | 22% | — | 7 jul 2014 | The BVSMWeb portal in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 10 does not properly implement access control, which allows remote attackers to… |
| CVE-2014-2198 | Alta (10) | 3.6% | — | 7 jul 2014 | Cisco Unified Communications Domain Manager (CDM) in Unified CDM Platform Software before 4.4.2 has a hardcoded SSH private key, which makes it easier for remote attackers to obtain access to the support and root… |
| CVE-2014-2197 | Alta (9) | 2.9% | — | 7 jul 2014 | The Administration GUI in the web framework in Cisco Unified Communications Domain Manager (CDM) in Unified CDM Application Software before 8.1.4 does not properly implement access control, which allows remote… |
| CVE-2014-3281 | Media (5) | 1.4% | — | 8 jun 2014 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to obtain potentially sensitive user information by visiting an… |
| CVE-2014-3278 | Media (5) | 1.4% | — | 8 jun 2014 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) does not properly implement access control, which allows remote attackers to enumerate accounts by visiting an unspecified BVSMWeb web page,… |
| CVE-2014-3280 | Media (4) | 2.0% | — | 3 jun 2014 | The web framework in VOSS in Cisco Unified Communications Domain Manager (CDM) 9.0(.1) and earlier does not properly implement access control, which allows remote authenticated users to obtain potentially sensitive user… |