Cisco Unity Connection Multiple Vulnerabilities, CVSS 6.5
Summary
CERT-Bund published security advisory WID-SEC-2026-1149 disclosing multiple vulnerabilities in Cisco Unity Connection (CVSS Base Score 6.5, medium). Affected versions include Cisco Unity Connection prior to 14SU6, 15SU4, and 14SU5. An attacker can exploit these flaws to conduct cross-site scripting attacks, redirect users to malicious websites, manipulate data, and disclose confidential information. Mitigations are available.
What changed
CERT-Bund disclosed multiple vulnerabilities in Cisco Unity Connection, a Voicemail and Integrated Messaging product. The vulnerabilities carry a CVSS Base Score of 6.5 (medium) and CVSS Temporal Score of 5.7 (medium), with remote attack capability confirmed.
Organizations using Cisco Unity Connection should identify if they are running affected versions (prior to 14SU6, 15SU4, or 14SU5) and apply available mitigations. The vulnerabilities enable cross-site scripting attacks, user redirection to malicious sites, data manipulation, and confidential information disclosure, posing risks to both data integrity and privacy.
Archived snapshot
Apr 17, 2026GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.
[WID-SEC-2026-1149] Cisco Unity Connection: Mehrere Schwachstellen CVSS Base Score 6.5 (mittel) CVSS Temporal Score 5.7 (mittel) Remoteangriff ja Datum 15.04.2026 Stand 16.04.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- CISCO Appliance
Produktbeschreibung
Cisco Unity Connection ist ein umfangreiches Voicemail und Integrated-Messaging- Produkt. Mit Cisco Unity Connection können Benutzer mit dem Cisco Unified Personal Communicator auf ihre Sprachnachrichten zugreifen, das Display ihres Cisco Unified IP-Telefons nutzen, um Sprachnachrichten anzuzeigen, zu sortieren und wiederzugeben, und sogar die Sprachsteuerung von Cisco Unity Connection verwenden, um auf Cisco Unified MeetingPlace Express Meetings zuzugreifen.
Produkte
15.04.2026
- Cisco Unity Connection <14SU6
Cisco Unity Connection <15SU4
Cisco Unity Connection <14SU5
Angriff
Angriff
Ein Angreifer kann mehrere Schwachstellen in Cisco Unity Connection ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, Benutzer auf bösartige Websites umzuleiten, Daten zu manipulieren und vertrauliche Informationen offenzulegen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Named provisions
Related changes
Get daily alerts for CERT-Bund Security Advisories
Daily digest delivered to your inbox.
Free. Unsubscribe anytime.
Source
About this page
Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission
Source document text, dates, docket IDs, and authority are extracted directly from CERT-Bund.
The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.
Classification
Who this affects
Taxonomy
Browse Categories
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.
Subscribed!
Optional. Filters your digest to exactly the updates that matter to you.