Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Avaya, Inc.

First CVE: Aug 7, 2001Active for: 25 yearsTotal CVEs: 139
36.5
VTI Score
Medium

Avaya's vulnerability footprint spans a modestly sized portfolio of enterprise communication and messaging platforms that sit centrally in business telephony, contact center, and unified messaging infrastructure. The vendor's disclosures frequently acquire public exploit code, reflecting the operational importance and accessibility of its Communication Manager, Modular Messaging, and S-series appliances to attackers seeking to disrupt or surveil corporate voice and messaging environments. The recurring weakness classes center on input-handling and information-disclosure issues—including cross-site scripting, improper input validation, and exposure of sensitive data—that are characteristic of complex, web-accessible administration interfaces and embedded network services. Defenders should prioritize patching these platforms, particularly internet-exposed instances and those managing sensitive call and message traffic; live exploitation and severity counts are shown alongside this summary.

FAUCET AI Generated
139
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Avaya, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 7, 2001
24 years ago
Most Recent CVE
Jun 12, 2025
407 days ago

Self-Reporting Analysis

Of all the CVEs published by Avaya, Inc. as a CNA, 100.0% affect products that Avaya, Inc. develops as a vendor.

100.0%
Self-reported: 45 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Avaya, Inc., 32.4% are self-published by Avaya, Inc. as a CNA.

32.4%
67.6%
Self-published: 45 (32.4%)
Other CNAs: 94 (67.6%)

Products(158 total)

Top CVEs

Signals from CVEs in this vendor scope (139 CVEs).

139 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-3811HIGH
Unrestricted file upload vulnerability in ImageUpload.ashx in the Wallboard application in Avaya IP Office Customer Call Reporter 7.0 before 7.0.5.8 Q1 2012 Maintenance Release and
Jul 3, 201210.080NOYES
CVE-2004-1050HIGH
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as
Dec 31, 200410.077NOYES
CVE-2007-1765HIGH
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code or cause a denial of service (persistent reboot) via a malfo
Mar 30, 20079.373NOYES
CVE-2004-0493MEDIUM
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error lead
Aug 6, 20046.472NOYES
CVE-2004-0212HIGH
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via
Aug 6, 200410.070NOYES
CVE-2004-0842HIGH
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain ma
Dec 23, 20047.561NOYES
CVE-2004-0841MEDIUM
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, ak
Dec 23, 20045.054NOYES
CVE-2004-0595MEDIUM
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows d
Jul 27, 20046.854NOYES
CVE-2004-0594MEDIUM
The memory_limit functionality in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, under certain conditions such as when register_globals is enabled, allows remote attackers to execute
Jul 27, 20045.151NOYES
CVE-2004-0201HIGH
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrar
Aug 6, 200410.048NONO
View all 139 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products139 CVEs
47%
43%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local24 (17.3%)
Network42 (30.2%)
Unknown73 (52.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low65 (46.8%)
High1 (0.7%)
Unknown73 (52.5%)
User Interaction
None51 (36.7%)
Unknown73 (52.5%)
Required15 (10.8%)
Privileges Required
Low33 (23.7%)
High8 (5.8%)
None25 (18.0%)
Unknown73 (52.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (139 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
1.4% of CVEs· 97th percentile
Nuclei
1 CVE
0.7% of CVEs· 95th percentile
ExploitDB
20 CVEs
14.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Avaya, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Avaya, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Avaya, Inc.'s Products

View all 7 CNAs →

Top CWEs