Skip to main content

Vendor/product archive

avaya / ip_office CVEs

Beta · best-effort

9 CVEs tagged to avaya / ip_office3 Critical, 4 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2024-4197

Published Jun 25, 2024

An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include al…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4196

Published Jun 25, 2024

An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Cont…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-25657

Published Sep 2, 2022

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affect…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7005

Published Aug 7, 2020

A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive informat…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-7030

Published Jun 4, 2020

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15614

Published Jan 23, 2019

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-15610

Published Sep 12, 2018

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP O…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2017-11309

Published Nov 10, 2017

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1