📦 Enterprise Chat And Email

by Cisco

🔍 What is Enterprise Chat And Email?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2025-20139

HIGH CVSS 7.5 Apr 2, 2025

An unauthenticated remote attacker can send specially crafted chat messages to Cisco Enterprise Chat and Email (ECE) to trigger a denial of service condition. The application stops responding and may ...

CVE-2024-20484

HIGH CVSS 7.5 Nov 6, 2024

An unauthenticated remote attacker can send crafted MR PIM traffic to Cisco Enterprise Chat and Email (ECE) to trigger a denial of service in the External Agent Assignment Service (EAAS). This prevent...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2025-20310

MEDIUM CVSS 6.1 Jul 2, 2025

A stored cross-site scripting (XSS) vulnerability in Cisco Enterprise Chat and Email web UI allows unauthenticated remote attackers to inject malicious scripts. When exploited, this could enable attac...

CVE-2022-20633

MEDIUM CVSS 5.3 Nov 15, 2024

This vulnerability in Cisco ECE allows unauthenticated remote attackers to enumerate valid usernames by analyzing differences in authentication responses. Attackers can confirm existing user accounts,...

CVE-2022-20631

MEDIUM CVSS 6.1 Nov 15, 2024

This vulnerability allows unauthenticated remote attackers to execute cross-site scripting (XSS) attacks against users of Cisco ECE's web management interface. Attackers can inject malicious scripts i...