Vulnerabilities > Avaya > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-07-19 CVE-2023-3722 Unrestricted Upload of File with Dangerous Type vulnerability in Avaya Aura Device Services
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file.
network
low complexity
avaya CWE-434
critical
9.8
2022-11-03 CVE-2022-38168 Missing Authentication for Critical Function vulnerability in Avaya products
Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
network
low complexity
avaya CWE-306
critical
9.1
2019-07-11 CVE-2019-7003 SQL Injection vulnerability in Avaya Control Manager
A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system.
network
low complexity
avaya CWE-89
critical
10.0
2018-10-17 CVE-2018-15616 Deserialization of Untrusted Data vulnerability in Avaya Aura System Platform
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution.
network
low complexity
avaya CWE-502
critical
9.8
2017-11-10 CVE-2017-11309 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Avaya IP Office
Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.
network
low complexity
avaya CWE-119
critical
9.6
2017-01-23 CVE-2016-2783 Data Processing Errors vulnerability in Avaya VSP Operating System Software 4.2.2.0/5.0.0.0
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
network
low complexity
avaya CWE-19
critical
9.8