Vulnerabilities > Cisco > Unified Communications Manager > 6.1.4b

DATE CVE VULNERABILITY TITLE RISK
2013-12-21 CVE-2013-6978 Information Exposure vulnerability in Cisco Unified Communications Manager
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249.
network
low complexity
cisco CWE-200
4.0
2013-11-18 CVE-2013-6689 Improper Input Validation vulnerability in Cisco Unified Communications Manager
Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229.
local
cisco CWE-20
6.9
2013-11-18 CVE-2013-6688 Path Traversal vulnerability in Cisco Unified Communications Manager
Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.
network
cisco CWE-22
6.3
2013-08-22 CVE-2013-3453 Resource Management Errors vulnerability in Cisco Unified Communications Manager and Unified Presence
Memory leak in Cisco Unified Communications Manager IM and Presence Service before 8.6(5)SU1 and 9.x before 9.1(2), and Cisco Unified Presence, allows remote attackers to cause a denial of service (memory and CPU consumption) by making many TCP connections to port (1) 5060 or (2) 5061, aka Bug ID CSCud84959.
network
low complexity
cisco CWE-399
7.8
2012-09-27 CVE-2012-3949 Improper Input Validation vulnerability in Cisco Ios, IOS XE and Unified Communications Manager
The SIP implementation in Cisco Unified Communications Manager (CUCM) 6.x and 7.x before 7.1(5b)su5, 8.x before 8.5(1)su4, and 8.6 before 8.6(2a)su1; Cisco IOS 12.2 through 12.4 and 15.0 through 15.2; and Cisco IOS XE 3.3.xSG before 3.3.1SG, 3.4.xS, and 3.5.xS allows remote attackers to cause a denial of service (service crash or device reload) via a crafted SIP message containing an SDP session description, aka Bug IDs CSCtw66721, CSCtj33003, and CSCtw84664.
network
low complexity
cisco CWE-20
7.8
2010-08-26 CVE-2010-2838 Unspecified vulnerability in Cisco Unified Communications Manager
The SendCombinedStatusInfo implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 7.0SU before 7.0(2a)SU3, 7.1 before 7.1(5), and 8.0 before 8.0(3) allows remote attackers to cause a denial of service (process failure) via a malformed SIP REGISTER message, aka Bug ID CSCtf66305.
network
low complexity
cisco
7.8
2010-08-26 CVE-2010-2837 Unspecified vulnerability in Cisco Unified Communications Manager
The SIPStationInit implementation in Cisco Unified Communications Manager (aka CUCM, formerly CallManager) 6.1SU before 6.1(5)SU1, 7.0SU before 7.0(2a)SU3, 7.1SU before 7.1(3b)SU2, 7.1 before 7.1(5), and 8.0 before 8.0(1) allows remote attackers to cause a denial of service (process failure) via a malformed SIP message, aka Bug ID CSCtd17310.
network
low complexity
cisco
7.8