Vulnerabilities > Avaya > IP Office > 11.1

DATE CVE VULNERABILITY TITLE RISK
2024-06-25 CVE-2024-4196 Unspecified vulnerability in Avaya IP Office
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component.
network
low complexity
avaya
critical
9.8
2024-06-25 CVE-2024-4197 Unrestricted Upload of File with Dangerous Type vulnerability in Avaya IP Office
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component.
network
low complexity
avaya CWE-434
critical
9.8
2022-09-02 CVE-2021-25657 Unspecified vulnerability in Avaya IP Office
A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges.
local
low complexity
avaya
7.8