Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Avaya — Vulnerabilities & Security Advisories 47

Browse all 47 CVE security advisories affecting Avaya. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Avaya operates primarily as a provider of enterprise communication solutions, including unified communications, contact center software, and networking hardware. The vendor’s portfolio has historically been associated with a significant volume of security flaws, currently totaling 47 recorded Common Vulnerabilities and Exposures (CVEs). These vulnerabilities predominantly involve remote code execution, cross-site scripting, and privilege escalation issues, often stemming from inadequate input validation or improper access controls within web interfaces and administrative panels. Notable incidents include critical flaws in IP Office and Session Manager products that allowed unauthenticated attackers to gain system-level access or execute arbitrary commands. The high count of CVEs reflects a pattern of legacy code vulnerabilities and delayed patch cycles for older on-premise deployments. Security researchers emphasize the necessity of rigorous network segmentation and immediate application of vendor-provided patches to mitigate the risk of exploitation in these communication infrastructure components.

CVE ID Title CVSS Severity Published
CVE-2020-7033 Avaya Equinox Conferencing XSS — Avaya Equinox Conferencing CWE-79 6.3 Medium 2020-11-12
CVE-2020-7029 Avaya Product System Management Interface Cross-Site Request Forgery Vulnerability — Avaya Aura Communication Manager CWE-352 6.4 Medium 2020-08-11
CVE-2019-7005 Unauthenticated Information Disclosure Vulnerability in IP Office — IP Office CWE-200 7.5 - 2020-08-07
CVE-2020-7030 IPO Information Disclosure — IP Office CWE-522 5.5 Medium 2020-06-03
CVE-2019-7007 Avaya Equinox Conferencing Management (iView) Directory Traversal Vulnerability — Equinox Conferencing Management (iView) CWE-22 7.5 High 2020-02-28
CVE-2019-7004 Avaya IP Office XSS Vulnerability — IP Office Application Server CWE-79 6.1 - 2019-12-11
CVE-2019-7000 Avaya Aura Conferencing XSS — Avaya Aura Conferencing CWE-79 6.1 - 2019-07-31
CVE-2019-7003 ACM SQL Injection — Avaya Control Manager CWE-89 9.1 - 2019-07-11
CVE-2019-7001 Avaya IPOCC WebUI SQL Injection — IP Office Contact Center CWE-89 8.1 - 2019-04-04
CVE-2018-15617 Communication Manager Denial of Service — Communication Manager CWE-399 7.5 - 2019-02-01
CVE-2018-15614 IP Office one-X Portal XSS — IP Office CWE-79 5.4 - 2019-01-23
CVE-2018-15616 System Platform Web UI Deserialization — Avaya Aura® System Platform CWE-502 9.8 - 2018-10-17
CVE-2018-15611 Communication Manager Local Administrator PrivEsc — Communication Manager CWE-284 6.7 - 2018-09-27
CVE-2018-15615 CMS Supervisor Information Disclosure — Call Management System Supervisor CWE-200 4.4 - 2018-09-24
CVE-2018-15613 Orchestration Designer Runtime Config XSS — Orchestration Designer CWE-79 6.1 - 2018-09-21
CVE-2018-15612 Orchestration Designer Runtime Config CSRF — Orchestration Designer CWE-352 8.8 - 2018-09-21
CVE-2018-15610 Improper access controls in IP Office one-X Portal — IP Office CWE-284 8.8 - 2018-09-12

This page lists every published CVE security advisory associated with Avaya. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.