Vulnerability index

Browse CVEs

100 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Equinox Conferencing MEDIUM 5.4
CVE-2020-7033

A Cross Site Scripting (XSS) Vulnerability on the Unified Portal Client (web client) used in Avaya Equinox Conferencing can allow an authenticated us…

Fix: 9.1.10+
Fix from $1,600 2020-11-13
Aura Communication Manager HIGH 8.8
CVE-2020-7029

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager…

Fix: 7.1 / 8.1.0.0+
Fix from $1,950 2020-08-11
Ip Office HIGH 7.5
CVE-2019-7005

A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc…

Fix: after 11.0.4.2
Fix from $1,950 2020-08-07
Ip Office MEDIUM 5.5
CVE-2020-7030

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…

Fix: after 11.0.4.2
Fix from $1,600 2020-06-04
Aura Conferencing HIGH 8.6
CVE-2019-7007

A directory traversal vulnerability has been found in the Avaya Equinox Management(iView)versions R9.1.9.0 and earlier. Successful exploitation could…

Fix: after 9.1.9.0
Fix from $1,950 2020-02-28
Ip Office Application Server MEDIUM 5.4
CVE-2019-7004

A Cross-Site Scripting (XSS) vulnerability in the WebUI component of IP Office Application Server could allow unauthorized code execution and potenti…

Fix: after 11.0.4.0
Fix from $1,600 2019-12-12
Aura Conferencing MEDIUM 6.1
CVE-2019-7000

A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive infor…

Fix: after 8.0
Fix from $1,600 2019-07-31
Control Manager CRITICAL 10.0
CVE-2019-7003

A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL co…

Fix: 8.0.4.0+
Fix from $2,300 2019-07-11
Ip Office Contact Center HIGH 8.8
CVE-2019-7001

A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive…

Fix: after 10.1.2.1
Fix from $1,950 2019-04-04
One X Communicator MEDIUM 5.5
CVE-2019-7006

Avaya one-X Communicator uses weak cryptographic algorithms in the client authentication component that could allow a local attacker to decrypt sensi…

Mitigation only
Fix from $1,600 2019-02-27
Aura Communication Manager HIGH 7.5
CVE-2018-15617

A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to c…

Fix: 7.1.3.2 / 8.0.1+
Fix from $1,950 2019-02-01
Ip Office MEDIUM 5.4
CVE-2018-15614

A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via field…

Mitigation only
Fix from $1,600 2019-01-23
Avaya Aura System Platform CRITICAL 9.8
CVE-2018-15616

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserializatio…

Fix: after 6.4.2
Fix from $2,300 2018-10-17
Aura Communication Manager MEDIUM 6.7
CVE-2018-15611

A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the l…

Fix: 7.1.3.1+
Fix from $1,600 2018-09-27
Orchestration Designer HIGH 8.8
CVE-2018-15612

A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administr…

Fix: 7.2.1+
Fix from $1,950 2018-09-21
Aura Orchestration Designer MEDIUM 6.1
CVE-2018-15613

A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content bei…

Fix: 7.2.1+
Fix from $1,600 2018-09-21
Ip Office HIGH 8.8
CVE-2018-15610

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A…

No fix yet
Fix from $1,950 2018-09-12
Aura HIGH 7.5
CVE-2018-6635

System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass inten…

Fix: after 7.1.1
Fix from $1,950 2018-02-05
Ip Office Contact Center HIGH 8.8
CVE-2017-12969EPSS 10%

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a de…

No fix yet
Fix from $1,950 2017-11-10
Ip Office CRITICAL 9.6
CVE-2017-11309EPSS 9%

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

Fix: 10.1.1+
Fix from $2,300 2017-11-10
Vsp Operating System Software CRITICAL 9.8
CVE-2016-2783

Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle …

Fix: after 4.2.2.0
Fix from $2,300 2017-01-23
Aura Application Server 5300 HIGH 10.0
CVE-2011-5096

Stack-based buffer overflow in cstore.exe in the Media Application Server (MAS) in Avaya Aura Application Server 5300 (formerly Nortel Media Applicat…

Mitigation only
Fix from $1,950 2012-07-03
Ip Office Customer Call Reporter HIGH 10.0
CVE-2012-3811EPSS 63%

Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 …

Mitigation only
Fix from $1,950 2012-07-03
Secure Access Link Gateway MEDIUM 5.0
CVE-2011-3008

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL …

Mitigation only
Fix from $1,600 2011-08-05
Communication Manager HIGH 9.0
CVE-2008-6708

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manage…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services HIGH 9.0
CVE-2008-6709

Unspecified vulnerability in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manage…

Mitigation only
Fix from $1,950 2009-04-10
Communication Manager HIGH 9.0
CVE-2008-6710

Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 all…

Mitigation only
Fix from $1,950 2009-04-10
Communication Manager HIGH 9.0
CVE-2008-6711

Unspecified vulnerability in the Web administration interface in Avaya Communication Manager 3.1.x before CM 3.1.4 SP2 and 4.0.x before 4.0.3 SP1 all…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services HIGH 7.8
CVE-2008-6706

Multiple unspecified vulnerabilities in the Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communica…

Mitigation only
Fix from $1,950 2009-04-10
Sip Enablement Services MEDIUM 6.4
CVE-2008-6707

The Web management interface in Avaya SIP Enablement Services (SES) 3.x and 4.0, as used with Avaya Communication Manager 3.1.x, does not perform aut…

Mitigation only
Fix from $1,600 2009-04-10