Skip to main content

Vendor archive

avaya CVEs

Beta · best-effort

139 CVEs tagged to vendor avaya22 Critical, 52 High, 61 Medium, 4 Low, 0 Unrated.

CVE-2025-1041

Published Jun 10, 2025

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions inclu…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-12756

Published Feb 11, 2025

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12755

Published Feb 11, 2025

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7480

Published Aug 8, 2024

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitr…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-7477

Published Aug 8, 2024

A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura Sy…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4197

Published Jun 25, 2024

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include al…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4196

Published Jun 25, 2024

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Cont…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-7031

Published Jan 17, 2024

Insecure Direct Object Reference vulnerabilities were discovered in the Avaya Aura Experience Portal Manager which may allow partial information disclosure to an authenticated non…

CVSS 5.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3722

Published Jul 19, 2023

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious up…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-3527

Published Jul 18, 2023

A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted da…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-2249

Published Oct 12, 2022

Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25657

Published Sep 2, 2022

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affect…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25654

Published Jun 25, 2021

An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 th…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25656

Published Jun 24, 2021

Stored XSS injection vulnerabilities were discovered in the Avaya Aura Experience Portal Web management which could allow an authenticated user to potentially disclose sensitive i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25655

Published Jun 24, 2021

A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions in…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25651

Published Jun 24, 2021

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avay…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25650

Published Jun 24, 2021

A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged use…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 139 CVEsPage 1 of 6