Aura System Manager

Vendor:

First CVE: Nov 16, 2009 · Active for 16 years

9
Total CVEs
More Total CVEs than 88% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Aura System Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2009
16 years ago
Most Recent CVE
Aug 8, 2024
718 days ago

CVE Severity & Scoring

Aura System Manager9 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local6 (66.7%)
Network3 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (55.6%)
High3 (33.3%)
None1 (11.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unli
Sep 30, 20108.145NOYES
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks v
Nov 13, 20206.524NONO
A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which c
Nov 15, 20197.524NONO
Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or
Sep 8, 20107.824NONO
The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, whic
Sep 8, 20107.823NONO
A SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary queries against the Avaya Aura Sys
Aug 8, 20246.720NONO
The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the dr
Nov 16, 20097.120NONO
The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump o
Sep 21, 20105.519NONO
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitra
Aug 8, 20244.416NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
11.1% of CVEs· 86th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Aura System Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.1.147.34.6%01
6.147.34.6%01
6.057.33.7%01
5.257.33.7%01
10.225.50.2%00