A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive information. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 through 11.0.4.2.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NAvaya Ip Office
APPAvaya10.0 – 10.1.0.711.0 – 11.0.4.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2024-4197CRITICAL9.9PL ✓same product
Unrestricted file upload umożliwiający RCE w Avaya IP Office (One-X)
CVE-2024-4196CRITICAL10.0PL ✓same product
RCE poprzez improper input validation w Avaya IP Office (Web Control)
CVE-2017-11309CRITICAL9.6PL ✓same product
Buffer overflow w Avaya IP Office SoftConsole — zdalne wykonanie kodu
CVE-2021-25657HIGH7.8same product
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may pot...
CVE-2016-5285HIGH7.5same product
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL che...