VYPR

IP Office

by Avaya

CVEs (8)

  • CVE-2017-11309CriNov 10, 2017
    risk 0.66cvss 9.6epss 0.09

    Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

  • CVE-2018-15610HigSep 12, 2018
    risk 0.48cvss 7.3epss 0.02

    A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

  • CVE-2020-7030Jun 3, 2020
    risk 0.03cvss epss 0.01

    A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though…

  • CVE-2024-4197Jun 25, 2024
    risk 0.00cvss epss 0.01

    An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.

  • CVE-2024-4196Jun 25, 2024
    risk 0.00cvss epss 0.01

    An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.

  • CVE-2021-25657Sep 2, 2022
    risk 0.00cvss epss 0.00

    A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

  • CVE-2019-7005Aug 7, 2020
    risk 0.00cvss epss 0.01

    A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2.

  • CVE-2018-15614Jan 23, 2019
    risk 0.00cvss epss 0.01

    A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler Service that could affect other application users. Affected versions of IP Office include 10.0…