Ip Office
Vendor:
First CVE: Nov 10, 2017 · Active for 8 years
9
Total CVEs
More Total CVEs than 86% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 69% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ip Office over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 10, 2017
8 years ago
Most Recent CVE
Jun 25, 2024
759 days ago
CVE Severity & Scoring
Ip Office9 CVEs
22%
44%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (22.2%)
Network7 (77.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (77.8%)
Unknown0 (0.0%)
Required2 (22.2%)
Privileges Required
Low4 (44.4%)
High0 (0.0%)
None5 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11309CRITICAL Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response. | Nov 10, 2017 | 9.6 | 38 | NO | YES |
CVE-2024-4197CRITICAL An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-4196CRITICAL An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Contr | Jun 25, 2024 | 9.8 | 29 | NO | NO |
CVE-2018-15610HIGH A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Of | Sep 12, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-25657HIGH A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects | Sep 2, 2022 | 7.8 | 26 | NO | NO |
CVE-2016-5285HIGH A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which c | Nov 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-7030MEDIUM A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to t | Jun 4, 2020 | 5.5 | 23 | NO | YES |
CVE-2019-7005HIGH A vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network access to gain sensitive informati | Aug 7, 2020 | 7.5 | 19 | NO | NO |
CVE-2018-15614MEDIUM A vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via fields in the Conference Scheduler S | Jan 23, 2019 | 5.4 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
22.2% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Ip Office
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.1 | 3 | 7.3 | 1.7% | 0 | 1 |
| 9.0 | 1 | 5.5 | 1.0% | 0 | 1 |
| 8.1 | 1 | 7.5 | 2.3% | 0 | 0 |
| 11.1 | 1 | 7.8 | 0.3% | 0 | 0 |
| 11.0 | 1 | 5.4 | 0.6% | 0 | 0 |
| 10.1 | 2 | 6.9 | 1.1% | 0 | 0 |
| 10.0 | 3 | 7.2 | 1.6% | 0 | 0 |