📦 Unified Communications Manager

by Cisco

🔍 What is Unified Communications Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-20309

CRITICAL CVSS 10.0 Jul 2, 2025

This critical vulnerability allows unauthenticated remote attackers to log into Cisco Unified Communications Manager systems using static root credentials that cannot be changed. Attackers gain full r...

CVE-2024-20253

CRITICAL CVSS 9.9 Jan 26, 2024

This critical vulnerability in Cisco Unified Communications and Contact Center Solutions allows unauthenticated remote attackers to execute arbitrary code on affected devices by sending crafted messag...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2026-20045

HIGH CVSS 8.2 Jan 21, 2026

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by sending crafted HTTP requests to the web managemen...

CVE-2024-20375

HIGH CVSS 8.6 Aug 21, 2024

An unauthenticated remote attacker can send a specially crafted SIP message to Cisco Unified Communications Manager systems, causing them to reload and creating a denial of service condition. This vul...

CVE-2023-20259

HIGH CVSS 8.6 Oct 4, 2023

An unauthenticated remote attacker can send crafted HTTP requests to a specific API endpoint in Cisco Unified Communications products, causing high CPU utilization that leads to denial of service. Thi...

CVE-2023-20211

HIGH CVSS 8.1 Aug 16, 2023

This vulnerability allows authenticated remote attackers to perform SQL injection attacks on Cisco Unified Communications Manager (Unified CM) and its Session Management Edition (SME) via the web-base...

CVE-2021-1362

HIGH CVSS 8.8 Apr 8, 2021

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on Cisco Unified Communications products via a crafted SOAP API request. It affects Cisco Unifie...

CVE-2025-20326

MEDIUM CVSS 4.3 Sep 3, 2025

This CSRF vulnerability in Cisco Unified Communications Manager allows unauthenticated remote attackers to trick authenticated users into performing unauthorized actions via malicious links. Affected ...

CVE-2025-20278

MEDIUM CVSS 6.0 Jun 4, 2025

This vulnerability allows authenticated local attackers with administrative credentials to execute arbitrary commands as root on affected Cisco Unified Communications products. The issue stems from im...

CVE-2020-3420

MEDIUM CVSS 5.4 Nov 18, 2024

This cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager allows authenticated attackers to inject malicious scripts into the web management interface. When exploited, it e...

CVE-2024-20511

MEDIUM CVSS 6.1 Nov 6, 2024

An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager web interface allows attackers to execute malicious scripts in users' browsers by tricking them into...

CVE-2024-20488

MEDIUM CVSS 6.1 Aug 21, 2024

An unauthenticated cross-site scripting (XSS) vulnerability in Cisco Unified Communications Manager web interface allows attackers to execute malicious scripts in users' browsers by tricking them into...