CVE-2021-1478

MEDIUM

Cisco Unified Communications Manager < 12.6 - Authenticated Denial of Service via JMX Port Access

Title source: llm
STIX 2.1

Description

A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an unsecured TCP/IP port. An attacker could exploit this vulnerability by accessing the port and restarting the JMX process. A successful exploit could allow the attacker to cause a DoS condition on an affected system.

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0023
EPSS Percentile 46.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
cisco/hosted_collaboration_mediation_fulfillment < 12.6
cisco/unified_communications_manager < 12.6 (2 CPE variants)
Published May 06, 2021
Tracked Since Feb 18, 2026