threat
engine
.sh
Back
·
··:··
Home
/
Product
/
avaya ip office
Product
avaya ip office
9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2024-4197
< 11.1.3.1
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution vi
9.9
CRITICAL
CVE-2024-4196
< 11.1.3.1
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution vi
10.0
CRITICAL
CVE-2021-25657
< 11.1
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a loc
7.8
HIGH
CVE-2019-7005
>= 10.0 and <= 10.1.0.7
A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated us
7.5
HIGH
CVE-2020-7030
>= 10.0 and <= 10.1.0.7
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially a
5.5
MEDIUM
CVE-2016-5285
all versions
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithS
7.5
HIGH
CVE-2018-15614
all versions
A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scriptin
6.8
MEDIUM
CVE-2018-15610
all versions
A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary fil
7.3
HIGH
CVE-2017-11309
< 10.1.1
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a l
9.6
CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin