Ifax develops HylaFAX, an enterprise fax transmission and management platform that handles document routing and system integration in communications infrastructure. The vendor's observed vulnerability exposure centers on race conditions in concurrent resource handling, OS command injection in fax-processing workflows, and improper permission assignment for critical resources—weakness classes typical of systems that parse untrusted input and manage privileged operations. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ifax over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-11766HIGH sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection. | May 19, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-15397HIGH HylaFAX+ through 7.0.2 and HylaFAX Enterprise have scripts that execute binaries from directories writable by unprivileged users (e.g., locations under /var/spool/hylafax that are | Jun 30, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-15396HIGH In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalat | Jun 30, 2020 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ifax.
Media articles that mention a CVE ID that affects a product developed by Ifax — matched by CVE ID, not by vendor name.