← Back

Avaya

avaya

139 CVEs • 158 products

Products (158)

Click to collapse
Toggle
S8300
s8300
S8500
s8500
S8700
s8700
S8100
s8100
Ip Office
ip_office
Intuity Audix
intuity_audix
S3400
s3400
Iq
iq
Argent Office
argent_office
Mn100
mn100
Cvlan
cvlan
Libsafe
libsafe
Sg200
sg200
Sg203
sg203
Sg208
sg208
Sg5
sg5
Vsu
vsu
Ip Soft Phone
ip_soft_phone
S8710
s8710
One X
one-x
Voice Portal
voice_portal
Media Server
media_server
Spaces
spaces
Intuity Lx
intuity_lx
Cajun M770 Atm
cajun_m770-atm
Cajun P130
cajun_p130
Cajun P330
cajun_p330
Cajun P550
cajun_p550
Cajun P550r
cajun_p550r
Cajun P580
cajun_p580
Cajun P880
cajun_p880
Cajun P882
cajun_p882
Wireless Ap 3
wireless_ap-3
Wireless Ap 4
wireless_ap-4
Wireless Ap 5
wireless_ap-5
Wireless Ap 6
wireless_ap-6
Wireless Ap 7
wireless_ap-7
Wireless Ap 8
wireless_ap-8
Vpnremote
vpnremote
Vsu 100
vsu_100
Vsu 10000
vsu_10000
Vsu 2000
vsu_2000
Vsu 7500
vsu_7500
Csu 5000
csu_5000
Voip Handset
voip_handset
Agent Access
agent_access
Callpilot
callpilot
Ip Agent
ip_agent

CVEs (139)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Avaya
1Aura Experience Portal
Nov 21, 2024
Jun 24, 2021
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix)...Show more
A vulnerability in the system Service Menu component of Avaya Aura Experience Portal may allow URL Redirection to any untrusted site through a crafted attack. Affected versions include 7.0 through 7.2.3 (without hotfix) and 8.0.0 (without hotfix).Show less
1Avaya
1Aura Appliance Virtualization Platform
Nov 21, 2024
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 version...Show more
A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.Show less
1Avaya
1Aura Appliance Virtualization Platform
Nov 21, 2024
Jun 24, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to acc...Show more
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.Show less
1Avaya
1Aura Utility Services
Nov 21, 2024
Jun 24, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services
1Avaya
1Aura Utility Services
Nov 21, 2024
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
4.6 MEDIUM· v2
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura...Show more
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility ServicesShow less
1Avaya
1Aura Utility Services
Nov 21, 2024
Jun 24, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and confi...Show more
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions of Avaya Aura Utility ServicesShow less
1Avaya
1Equinox Conferencing
Nov 21, 2024
Apr 28, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected...Show more
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Management component of Avaya Equinox Conferencing include all 3.x versions before 3.17. Avaya Equinox Conferencing is now offered as Avaya Meetings Server.Show less
1Avaya
1Equinox Conferencing
Nov 21, 2024
Apr 28, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system o...Show more
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The affected versions of Avaya Equinox Conferencing includes all 9.x versions before 9.1.11. Equinox Conferencing is now offered as Avaya Meetings Server.Show less
1Avaya
1Callback Assist
Nov 21, 2024
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assi...Show more
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.Show less
1Avaya
1Aura Orchestration Designer
Nov 21, 2024
Apr 23, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affec...Show more
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.Show less
1Avaya
1Session Border Controller For Enterprise
Nov 21, 2024
Apr 23, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system...Show more
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affected versions of Avaya Session Border Controller for Enterprise include 7.x, 8.0 through 8.1.1.xShow less
1Avaya
2Aura System Manager
Weblm
Nov 21, 2024
Nov 13, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affe...Show more
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.Show less
1Avaya
1Equinox Conferencing
Nov 21, 2024
Nov 13, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions of Equinox Conferencin...Show more
A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated user to perform XSS attacks. The affected versions of Equinox Conferencing includes all 9.x versions before 9.1.10.Show less
1Avaya
2Aura Communication Manager
Aura Messaging
Nov 21, 2024
Aug 11, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenti...Show more
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.Show less
1Avaya
1Ip Office
Nov 21, 2024
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office inclu...Show more
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2.Show less
1Avaya
1Ip Office
Nov 21, 2024
Jun 4, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Of...Show more
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.Show less
1Avaya
1Aura Conferencing
Nov 21, 2024
Feb 28, 2020
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are...Show more
A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could potentially allow an unauthenticated attacker to access files that are outside the restricted directory on the remote server.Show less
1Avaya
1Ip Office Application Server
Nov 21, 2024
Dec 12, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affe...Show more
A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potentially disclose sensitive information. All product versions 11.x are affected. Product versions prior to 11.0, including unsupported versions, were not evaluated.Show less
5Avaya
DebianMozilla+2 more
27Aura Application Enablement Services
Aura Application Server 5300Aura Communication Manager+24 more
Nov 21, 2024
Nov 15, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a...Show more
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.Show less
1Avaya
1Aura Conferencing
Nov 21, 2024
Jul 31, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x ve...Show more
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.Show less