Avaya, Inc.
First CVE: Sep 12, 2018Active for: 8 years
45
CVEs Published
More CVEs Published than 55% of tracked CNAs
5.6
Avg CVEs / Year
More Avg CVEs / Year than 36% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Avaya, Inc. as a CNA, 100.0% affect products that Avaya, Inc. develops as a vendor.
100.0%
Self-reported: 45Third-party: 0
Of all the CVEs published that affect products developed by Avaya, Inc., 32.4% are self-published by Avaya, Inc. as a CNA.
32.4%
67.6%
Self-published: 45Published by other CNAs: 94
Trends Over Time
The number and severity of CVEs published by Avaya, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2018
7 years ago
Most Recent CVE
Jun 10, 2025
409 days ago
Top CVEs
All CVEs published by Avaya, Inc. as a CNA, regardless of affected vendor or product.
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-3722CRITICAL An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious upl | Jul 19, 2023 | 9.8 | 40 | NO | YES |
CVE-2018-15616CRITICAL A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in r | Oct 17, 2018 | 9.8 | 32 | NO | NO |
CVE-2019-7003CRITICAL A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive d | Jul 11, 2019 | 10.0 | 30 | NO | NO |
CVE-2024-4197CRITICAL An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-4196CRITICAL An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Contr | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-1041CRITICAL An improper input validation discovered in
Avaya Call Management System
could allow an unauthorized
remote command via a specially crafted web request. Affected versions includ | Jun 10, 2025 | 9.8 | 28 | NO | NO |
CVE-2018-15612HIGH A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versio | Sep 21, 2018 | 8.8 | 28 | NO | NO |
CVE-2020-7029HIGH A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This | Aug 11, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-7001HIGH A SQL injection vulnerability in the WebUI component of IP Office Contact Center could allow an authenticated attacker to retrieve or alter sensitive data related to other users on | Apr 4, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-15610HIGH A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Of | Sep 12, 2018 | 8.8 | 27 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA45 CVEs
53%
33%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local15 (33.3%)
Network30 (66.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None33 (73.3%)
Unknown0 (0.0%)
Required12 (26.7%)
Privileges Required
Low21 (46.7%)
High8 (17.8%)
None16 (35.6%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (45 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.2% of CVEs· 86th percentile
ExploitDB
2 CVEs
4.4% of CVEs· 94th percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Avaya, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Avaya, Inc. as a CNA — matched by CVE ID, not by organization name.