IPO Information Disclosure
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 5.5epss 1.0%
from disclosure to weapon9 days
Published on NVDJun 3
1st PoC+9d
exploitation probability
1.0%top 41% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Avaya · IP Officepublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/48581unverifiedcve_referencepacketstormsecurity.com/files/157957/Avaya-IP-Office-11-Insecure-Transit-Password-Disclosure.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.