MEDIUM
IPO Information Disclosure
Published Jun 3, 2020
5.5
MEDIUMCVSS 3.1
EPSS 1.04%
Description
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.
Affected products
-
- Version 10.0StatusaffectedConstraints<10.1.0.8
- Version 11.0StatusaffectedConstraints<11.0.4.3
- Version 9.xStatusaffectedConstraints-
- Version
OR
- ≥ 10.0 · ≤ 10.1.0.7
- ≥ 11.0 · ≤ 11.0.4.2
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.0
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
- 9.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (4)
- http://packetstormsecurity.com/files/157957/Avaya-IP-Office-11-Insecure-Transit-Password-Disclosure.html x_refsource_MISC
- http://seclists.org/fulldisclosure/2020/Jun/12 mailing-listx_refsource_FULLDISC
- https://downloads.avaya.com/css/P8/documents/101067493 x_refsource_CONFIRMVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28164 Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/157957/Avaya-IP-Office-11-Insecure-Transit-Password-Disclosure.html | x_refsource_MISC | |
| http://seclists.org/fulldisclosure/2020/Jun/12 | mailing-listx_refsource_FULLDISC | |
| https://downloads.avaya.com/css/P8/documents/101067493 | x_refsource_CONFIRMVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-28164 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner avaya
Published Jun 3, 2020
Updated Sep 16, 2024
Reserved Jan 14, 2020
Link CVE-2020-7030
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2020-28164 Assigner avaya
Published Jun 3, 2020
Updated Sep 16, 2024
Exploited since n/a
Link EUVD-2020-28164