Show filters
137 Total Results
Displaying 21-30 of 137
Sort by:
Attacker Value
Unknown
CVE-2021-25651
Disclosure Date: June 24, 2021 (last updated November 08, 2023)
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to escalate privileges. Affects all 7.x versions of Avaya Aura Utility Services
0
Attacker Value
Unknown
CVE-2021-25652
Disclosure Date: June 24, 2021 (last updated November 08, 2023)
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.
0
Attacker Value
Unknown
CVE-2021-25653
Disclosure Date: June 24, 2021 (last updated November 28, 2024)
A privilege escalation vulnerability was discovered in Avaya Aura Appliance Virtualization Platform Utilities (AVPU) that may potentially allow a local user to escalate privileges. Affects 8.0.0.0 through 8.1.3.1 versions of AVPU.
0
Attacker Value
Unknown
CVE-2021-25649
Disclosure Date: June 24, 2021 (last updated November 08, 2023)
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions of Avaya Aura Utility Services
0
Attacker Value
Unknown
CVE-2020-7037
Disclosure Date: April 28, 2021 (last updated November 28, 2024)
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system or even potentially lead to a denial of service. The affected versions of Avaya Equinox Conferencing includes all 9.x versions before 9.1.11. Equinox Conferencing is now offered as Avaya Meetings Server.
0
Attacker Value
Unknown
CVE-2020-7038
Disclosure Date: April 28, 2021 (last updated November 08, 2023)
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Management component of Avaya Equinox Conferencing include all 3.x versions before 3.17. Avaya Equinox Conferencing is now offered as Avaya Meetings Server.
0
Attacker Value
Unknown
CVE-2020-7034
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affected versions of Avaya Session Border Controller for Enterprise include 7.x, 8.0 through 8.1.1.x
0
Attacker Value
Unknown
CVE-2020-7035
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.
0
Attacker Value
Unknown
CVE-2020-7036
Disclosure Date: April 23, 2021 (last updated November 28, 2024)
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.
0
Attacker Value
Unknown
CVE-2020-7032
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. Affected versions of Avaya WebLM include: 7.0 through 7.1.3.6 and 8.0 through 8.1.2.
0