Vulnerability index

Browse CVEs

42 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Media Server MEDIUM 6.5
CVE-2025-49186

The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptibl…

Mitigation only
Fix from $1,600 2025-06-12
Spaces MEDIUM 6.1
CVE-2024-12756

An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the …

Mitigation only
Fix from $1,600 2025-02-11
Spaces MEDIUM 5.4
CVE-2024-12755

A Cross-Site Scripting (XSS) vulnerability in Avaya Spaces may have allowed unauthorized code execution and potential disclose of sensitive informati…

Mitigation only
Fix from $1,600 2025-02-11
Ix Workforce Engagement MEDIUM 6.5
CVE-2023-31187

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials

No fix yet
Fix from $1,600 2023-05-30
Ix Workforce Engagement MEDIUM 6.1
CVE-2023-32218

Avaya IX Workforce Engagement v15.2.7.1195 - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Mitigation only
Fix from $1,600 2023-05-30
Ix Workforce Engagement MEDIUM 5.3
CVE-2023-31186

Avaya IX Workforce Engagement v15.2.7.1195 - User Enumeration - Observable Response Discrepancy

Mitigation only
Fix from $1,600 2023-05-30
Scopia Pathfinder 10 Pts Firmware CRITICAL 9.1
CVE-2022-38168

Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to by…

No fix yet
Fix from $2,300 2022-11-03
One X Communicator MEDIUM 5.5
CVE-2019-7006

Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensi…

Mitigation only
Fix from $1,600 2019-02-27
Ip Office MEDIUM 5.4
CVE-2018-15614

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via field…

Mitigation only
Fix from $1,600 2019-01-23
Ip Office HIGH 8.8
CVE-2018-15610

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A…

No fix yet
Fix from $1,950 2018-09-12
Ip Office Contact Center HIGH 8.8
CVE-2017-12969EPSS 10%

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a de…

No fix yet
Fix from $1,950 2017-11-10
Aura Application Server 5300 HIGH 10.0
CVE-2011-5096

Stack-based buffer overflow in cstore.exe in the Media Application Server (MAS) in Avaya Aura Application Server 5300 (formerly Nortel Media Applicat…

Mitigation only
Fix from $1,950 2012-07-03
Ip Office Customer Call Reporter HIGH 10.0
CVE-2012-3811EPSS 63%

Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 …

Mitigation only
Fix from $1,950 2012-07-03
Secure Access Link Gateway MEDIUM 5.0
CVE-2011-3008

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL …

Mitigation only
Fix from $1,600 2011-08-05
Communication Manager HIGH 9.0
CVE-2008-6708

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manage…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services HIGH 9.0
CVE-2008-6709

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manage…

Mitigation only
Fix from $1,950 2009-04-10
Communication Manager HIGH 9.0
CVE-2008-6710

Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 all…

Mitigation only
Fix from $1,950 2009-04-10
Communication Manager HIGH 9.0
CVE-2008-6711

Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 all…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services HIGH 7.8
CVE-2008-6706

Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communica…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services MEDIUM 6.4
CVE-2008-6707

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform aut…

Mitigation only
Fix from $1,600 2009-04-10
Communication Manager HIGH 7.5
CVE-2008-6574

Unspecified vulnerability in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote attackers to gain privileges an…

Mitigation only
Fix from $1,950 2009-04-01
Communication Manager MEDIUM 6.8
CVE-2008-6575

Unspecified vulnerability in the SIP server in SIP Enablement Services (SES) in Avaya Communication Manager 3.1.x and 4.x allows remote authenticated…

Mitigation only
Fix from $1,600 2009-04-01
One X MEDIUM 5.0
CVE-2008-6140

Unspecified vulnerability in the Session Initiation Protocol (SIP) implementation in Avaya one-X Desktop Edition 2.1.0.78 allows remote attackers to …

No fix yet
Fix from $1,600 2009-02-14
Ip Soft Phone MEDIUM 5.0
CVE-2008-6141

Unspecified vulnerability in Avaya IP Softphone 6.0 SP4 and 6.01.85 allows remote attackers to cause a denial of service (crash) via a large amount o…

Mitigation only
Fix from $1,600 2009-02-14
Communication Manager HIGH 9.0
CVE-2008-5709

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1 before 3.1.4 SP2, 4.0 before 4.0.3 SP1, …

Mitigation only
Fix from $1,950 2008-12-24
Communication Manager MEDIUM 5.0
CVE-2008-5710

Multiple unspecified vulnerabilities in the web management interface in Avaya Communication Manager (CM) 3.1.x, 4.0.3, and 5.x allow remote attackers…

No fix yet
Fix from $1,600 2008-12-24
Sip Enablement Services HIGH 7.5
CVE-2008-3778

The remote management interface in SIP Enablement Services (SES) Server in Avaya SIP Enablement Services 5.0, and Communication Manager (CM) 5.0 on t…

Mitigation only
Fix from $1,950 2008-08-25
Messaging Storage Server MEDIUM 6.5
CVE-2008-3081

Multiple unspecified "input validation" vulnerabilities in the Web management interface (aka Messaging Administration interface) in Avaya Message Sto…

Mitigation only
Fix from $1,600 2008-07-09
Voip Handset HIGH 7.8
CVE-2007-5556

Unspecified vulnerability in the Avaya VoIP Handset allows remote attackers to cause a denial of service (reboot) via crafted packets. NOTE: as of 20…

No fix yet
Fix from $1,950 2007-10-18
4602sw Ip Phone HIGH 7.5
CVE-2007-3319

The Avaya 4602SW IP Phone (Model 4602D02A) with 2.2.2 and earlier SIP firmware does not use the cnonce parameter in the Authorization header of SIP r…

Mitigation only
Fix from $1,950 2007-06-21