📦 Unity Connection

by Cisco

🔍 What is Unity Connection?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-20253

CRITICAL CVSS 9.9 Jan 26, 2024

This critical vulnerability in Cisco Unified Communications and Contact Center Solutions allows unauthenticated remote attackers to execute arbitrary code on affected devices by sending crafted messag...

CVE-2021-44228

CRITICAL CVSS 10.0 Dec 10, 2021

CVE-2021-44228 (Log4Shell) is a critical remote code execution vulnerability in Apache Log4j2 that allows attackers to execute arbitrary code by exploiting JNDI lookups in log messages. This affects a...

CVE-2026-20045

HIGH CVSS 8.2 Jan 21, 2026

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected Cisco Unified Communications systems by sending crafted HTTP requests to the web managemen...

CVE-2024-20272

HIGH CVSS 7.3 Jan 17, 2024

An unauthenticated remote attacker can upload arbitrary files and execute commands on Cisco Unity Connection systems via a vulnerable API in the web management interface. This allows complete system c...

CVE-2023-20259

HIGH CVSS 8.6 Oct 4, 2023

An unauthenticated remote attacker can send crafted HTTP requests to a specific API endpoint in Cisco Unified Communications products, causing high CPU utilization that leads to denial of service. Thi...

CVE-2021-1362

HIGH CVSS 8.8 Apr 8, 2021

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on Cisco Unified Communications products via a crafted SOAP API request. It affects Cisco Unifie...

CVE-2025-20278

MEDIUM CVSS 6.0 Jun 4, 2025

This vulnerability allows authenticated local attackers with administrative credentials to execute arbitrary commands as root on affected Cisco Unified Communications products. The issue stems from im...