CVE-2016-9210: Cisco Unified Communications Manager

High severity, CVSS 7.5. EPSS: 3% chance of exploitation in the next 30 days.

A vulnerability in the Cisco Unified Reporting upload tool accessed via the Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to modify arbitrary files on the file system. More Information: CSCvb61698. Known Affected Releases: 11.5(1.11007.2). Known Fixed Releases: 12.0(0.98000.168) 12.0(0.98000.178) 12.0(0.98000.399) 12.0(0.98000.510) 12.0(0.98000.536) 12.0(0.98500.7).

Affected products

  • Cisco Unified Communications Manager: version 11.5(1.11007.2) only

Published 2016-12-14. Last modified 2026-06-17.