← Vulnerability feed

Vulnerability record · CVE-2015-0680 · published 28 March 2015

CVE-2015-0680: Cisco unified callmanager information exposure vulnerability

Cisco · Unified Callmanager

Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.

4.0 CVSS 2.0 Medium EPSS 1.3% · top 30.2% CWE-200 · Information exposure
4.0CVSS 2.0 base score
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Cisco Unified Call Manager (CM) 9.1(2.1000.28) does not properly restrict resource requests, which allows remote authenticated users to read arbitrary files via unspecified vectors, aka Bug ID CSCuq44439.

AV:N/AC:L/Au:S/C:P/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-0680 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2008-0027Cisco Unified Communications Manager CTL Provider heap buffer overflowThe Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager and CallManager contains a heap-based buf…EPSS 57%analysed10.0CVE-2007-5538Cisco unified callmanager memory buffer overflow vulnerabilityBuffer overflow in the Centralized TFTP File Locator Service in Cisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(3), …EPSS 5.5%10.0CVE-2006-5278Cisco unified callmanager vulnerabilityInteger overflow in the Real-Time Information Server (RIS) Data Collector service (RisDC.exe) in Cisco Unified Communications Manager (CUCM, formerly…EPSS 8.9%9.3CVE-2006-5277Cisco unified callmanager vulnerabilityOff-by-one error in the Certificate Trust List (CTL) Provider service (CTLProvider.exe) in Cisco Unified Communications Manager (CUCM, formerly CallM…EPSS 9.6%7.8CVE-2009-2864Cisco unified callmanager vulnerabilityCisco Unified Communications Manager (aka CUCM, formerly CallManager) 5.x before 5.1(3g), 6.x before 6.1(4), 7.0.x before 7.0(2a)su1, and 7.1.x befor…EPSS 2.9%7.8CVE-2008-1744Cisco unified callmanager improper input validation vulnerabilityThe Certificate Authority Proxy Function (CAPF) service in Cisco Unified Communications Manager (CUCM) 4.1 before 4.1(3)SR7, 4.2 before 4.2(3)SR4, an…EPSS 1.2%7.8CVE-2007-5537Cisco unified callmanager vulnerabilityCisco Unified Communications Manager (CUCM, formerly CallManager) 5.1 before 5.1(2), and Unified CallManager 5.0, allow remote attackers to cause a d…EPSS 2.0%7.8CVE-2007-1834Cisco unified callmanager vulnerabilityCisco Unified CallManager (CUCM) 5.0 before 5.0(4a)SU1 and Cisco Unified Presence Server (CUPS) 1.0 before 1.0(3) allow remote attackers to cause a d…EPSS 1.9%

Source: NIST National Vulnerability Database (record CVE-2015-0680), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.