Home/Product/avaya ip office
Product

avaya ip office

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2024-4197
< 11.1.3.1
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution vi
9.9CRITICAL
CVE-2024-4196
< 11.1.3.1
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution vi
10.0CRITICAL
CVE-2021-25657
< 11.1
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a loc
7.8HIGH
CVE-2019-7005
>= 10.0 and <= 10.1.0.7
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated us
7.5HIGH
CVE-2020-7030
>= 10.0 and <= 10.1.0.7
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially a
5.5MEDIUM
CVE-2016-5285
all versions
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithS
7.5HIGH
CVE-2018-15614
all versions
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scriptin
6.8MEDIUM
CVE-2018-15610
all versions
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary fil
7.3HIGH
CVE-2017-11309
< 10.1.1
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a l
9.6CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin