Avaya Vulnerabilities and Affected Products
Vulnerabilities associated with IP Office.
Products
Clear product- IP Office7 vulnerabilities
- Avaya Aura Utility Services3 vulnerabilities
- ip600_media_servers3 vulnerabilities
- IX Workforce Engagement3 vulnerabilities
- Aura System Manager2 vulnerabilities
- Avaya Aura Appliance Virtualization Platform Utilities2 vulnerabilities
- Avaya Aura Communication Manager2 vulnerabilities
- Avaya Call Management System2 vulnerabilities
- Avaya Spaces2 vulnerabilities
- Communication Manager2 vulnerabilities
- ip_office2 vulnerabilities
- Orchestration Designer2 vulnerabilities
- Aura Device Services1 vulnerability
- Aura Orchestration Designer1 vulnerability
- aura_device_services1 vulnerability
- aura_system_manager1 vulnerability
- aura_utility_services1 vulnerability
- Avaya Aura Application Enablement Services1 vulnerability
- Avaya Aura Conferencing1 vulnerability
- Avaya Aura Devices Services1 vulnerability
- Avaya Aura Messaging1 vulnerability
- Avaya Aura® System Platform1 vulnerability
- Avaya Control Manager1 vulnerability
- Avaya Equinox Conferencing1 vulnerability
- Avaya Experience Portal1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-4197CRITICAL | Avaya IP Office One-X Portal File Upload VulnerabilityAn unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1. CWE-434Jun 25, 2024 | CVSS9.9v3.1 | EPSS0.777% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-4196CRITICAL | Avaya IP Office Web Control RCE VulnerabilityAn improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1. | CVSS10.0v3.1 | EPSS0.587% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25657HIGH | Avaya IP Office Privilege Escalation VulnerabilityA privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions. CWE-269Sep 2, 2022 | CVSS7.8v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-7005HIGH | Unauthenticated Information Disclosure Vulnerability in IP OfficeA vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2. CWE-200Aug 7, 2020 | CVSS7.5v3.1 | EPSS1.2% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7030MEDIUM | IPO Information DisclosureA sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3. | CVSS5.5v3.1 | EPSS1% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15614MEDIUM | IP Office one-X Portal XSSA vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0 through 10.1 SP3 and 11.0 versions prior to 11.0 SP1. CWE-79Jan 23, 2019 | CVSS6.8v3.0 | EPSS0.621% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-15610HIGH | Improper access controls in IP Office one-X PortalA vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2. | CVSS7.3v3.0 | EPSS1.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |