VYPR
Vendor

Avaya

Avaya LLC, formerly Avaya Inc., is an American multinational technology company headquartered in Morristown, New Jersey, that provides cloud communications and workstream collaboration services. The company's platform includes unified communications and contact center services. In 2019, the company provided services to 220,000 customer locations in 190 countries.

Founded 2000
Products
164
CVEs
141
Across products
234
Status
Private

Products

164
View all 164 products →

Recent CVEs

141
View all 141 CVEs →
  • CVE-2017-11309CriNov 10, 2017
    risk 0.66cvss 9.6epss 0.09

    Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

  • CVE-2024-4196CriJun 25, 2024
    risk 0.65cvss 10.0epss 0.01

    An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.

  • CVE-2019-7003CriJul 11, 2019
    risk 0.65cvss 10.0epss 0.01

    A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Control Manager include 7.x…

  • CVE-2025-1041CriJun 10, 2025
    risk 0.64cvss 9.9epss 0.00

    An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

  • CVE-2024-4197CriJun 25, 2024
    risk 0.64cvss 9.9epss 0.01

    An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.

  • CVE-2019-7001CriApr 4, 2019
    risk 0.64cvss 9.9epss 0.01

    A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on the system. Affected versions of IP Office Contact Center include all 9.x and 10.x versions prior…

  • CVE-2016-2783CriJan 23, 2017
    risk 0.64cvss 9.8epss 0.04

    Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.

  • CVE-2017-12969HigNov 10, 2017
    risk 0.61cvss 8.8epss 0.10

    Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.

  • CVE-2022-38168CriNov 3, 2022
    risk 0.59cvss 9.1epss 0.01

    Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.

  • CVE-2018-15616CriOct 17, 2018
    risk 0.59cvss 9.0epss 0.03

    A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0…

  • CVE-2010-2943HigSep 30, 2010
    risk 0.57cvss 8.1epss 0.17

    The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were…

  • CVE-2023-3722HigJul 19, 2023
    risk 0.56cvss 8.6epss 0.04

    An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

  • CVE-2018-15613HigSep 21, 2018
    risk 0.54cvss 8.3epss 0.01

    A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

  • CVE-2018-15612HigSep 21, 2018
    risk 0.54cvss 8.3epss 0.00

    A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

  • CVE-2020-7037HigApr 28, 2021
    risk 0.53cvss 8.1epss 0.01

    An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The…

  • CVE-2020-7036HigApr 23, 2021
    risk 0.53cvss 8.1epss 0.01

    An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.

  • CVE-2020-7035HigApr 23, 2021
    risk 0.53cvss 8.1epss 0.01

    An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer…

  • CVE-2021-25653HigJun 24, 2021
    risk 0.52cvss 8.0epss 0.01

    A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.

  • CVE-2021-25651HigJun 24, 2021
    risk 0.52cvss 8.0epss 0.00

    A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services

  • CVE-2024-12755HigFeb 11, 2025
    risk 0.51cvss 7.9epss 0.00

    A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive information.