CVE-2013-5534: Cisco Unity Connection

Medium severity, CVSS 4.0. EPSS: 1.5% chance of exploitation in the next 30 days.

Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a crafted pathname for a file that is not a valid audio file, aka Bug ID CSCuj22948.

Affected products

  • Cisco Unity Connection: affected versions not specified

Published 2013-10-19. Last modified 2026-06-16.