« Volver al listado

Cisco

Cisco Unified Communications Manager IM AND Presence Service: vulnerabilidades y CVE

Cisco Unified Communications Manager IM AND Presence Service tiene 40 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.

CVE40
Últimos 12 meses1
Críticas4
Explotadas activamente2

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

🔴 Explotadas activamente (CISA KEV)

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-20045Crítica (9.8)4.5%⚠ Explotación activa21 ene 2026
—
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-20045Crítica (9.8)4.5%⚠ Explotación activa21 ene 2026
—
CVE-2025-20330Media (6.1)0.25%—3 sept 2025
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site…
CVE-2025-20278Media (6.7)0.18%—4 jun 2025
A vulnerability in the CLI of multiple Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device as the…
CVE-2020-3532Media (6.1)0.50%—18 nov 2024
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM…
CVE-2024-20457Media (6.5)0.44%—6 nov 2024
A vulnerability in the logging component of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to view sensitive information in clear text…
CVE-2024-20310Media (6.1)0.50%—3 abr 2024
A vulnerability in the web-based interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack…
CVE-2024-20253Crítica (10)2.4%—26 ene 2024
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due…
CVE-2023-20242Media (6.1)0.49%—16 ago 2023
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM &…
CVE-2023-20108Alta (7.5)0.93%—28 jun 2023
A vulnerability in the XCP Authentication Service of the Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an unauthenticated, remote attacker to cause a temporary service…
CVE-2022-20859Alta (8.8)1.3%—6 jul 2022
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection…
CVE-2022-20815Media (6.1)0.76%—6 jul 2022
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified CM Session Management Edition (Unified CM SME), and Cisco Unified Communications Manager IM &…
CVE-2022-20800Media (6.1)0.76%—6 jul 2022
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications…
CVE-2022-20791Media (6.5)1.5%—6 jul 2022
A vulnerability in the database user privileges of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified Communications…
CVE-2022-20786Alta (8.1)0.84%—21 abr 2022
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an authenticated, remote attacker to conduct SQL injection…
CVE-2021-44228Crítica (10)100%⚠ Explotación activa10 dic 2021
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other…
CVE-2021-34773Media (6.5)0.50%—4 nov 2021
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), and Cisco Unified…
CVE-2021-34701Media (4.3)1.6%—4 nov 2021
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications…
CVE-2021-1365Alta (8.1)1.1%—6 may 2021
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an…
CVE-2021-1363Alta (8.1)1.1%—6 may 2021
Multiple vulnerabilities in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service could allow an authenticated, remote attacker to conduct SQL injection attacks on an…
CVE-2021-1364Media (4.9)1.3%—20 ene 2021
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system.…
CVE-2021-1357Media (6.5)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system.…
CVE-2021-1355Media (6.5)1.4%—20 ene 2021
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system.…
CVE-2021-1282Media (4.9)1.3%—20 ene 2021
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) could allow an attacker to conduct path traversal attacks and SQL injection attacks on an affected system.…
CVE-2020-27121Media (6.5)1.2%—6 nov 2020
A vulnerability in Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P) Software could allow an authenticated, remote attacker to cause the Cisco XCP Authentication Service on an affected…
CVE-2020-3282Media (6.1)0.80%—2 jul 2020
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence…
CVE-2019-1915Media (6.5)0.67%—2 oct 2019
A vulnerability in the web-based interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition (SME), Cisco Unified Communications Manager IM and Presence (Unified CM…
CVE-2019-12707Media (6.1)1.1%—2 oct 2019
A vulnerability in the web-based interface of multiple Cisco Unified Communications products could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based…
CVE-2019-1845Alta (8.6)4.6%—5 jun 2019
A vulnerability in the authentication service of the Cisco Unified Communications Manager IM and Presence (Unified CM IM&P) Service, Cisco TelePresence Video Communication Server (VCS), and Cisco Expressway Series…
CVE-2018-15403Media (5.4)1.2%—5 oct 2018
A vulnerability in the web interface of Cisco Emergency Responder, Cisco Unified Communications Manager, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an…
CVE-2018-0409Alta (7.5)3.5%—15 ago 2018
A vulnerability in the XCP Router service of the Cisco Unified Communications Manager IM & Presence Service (CUCM IM&P) and the Cisco TelePresence Video Communication Server (VCS) and Expressway could allow an…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1059 Command and Scripting Interpreter1
  3. T1068 Exploitation for Privilege Escalation1
  4. T1189 Drive-by Compromise1
  5. T1204.002 Malicious File1
  6. T1566 Phishing1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

📰 Noticias relacionadas

Otros productos de Cisco