CVE-2018-15610

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
avayaCNA
7.3 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
VendorProductVersion
avayaip_office
9.1
avayaip_office
9.1:sp1
avayaip_office
9.1:sp10
avayaip_office
9.1:sp11
avayaip_office
9.1:sp12
avayaip_office
9.1:sp2
avayaip_office
9.1:sp3
avayaip_office
9.1:sp4
avayaip_office
9.1:sp5
avayaip_office
9.1:sp6
avayaip_office
9.1:sp7
avayaip_office
9.1:sp8
avayaip_office
9.1:sp9
avayaip_office
10.0
avayaip_office
10.0:sp1
avayaip_office
10.0:sp2
avayaip_office
10.0:sp3
avayaip_office
10.0:sp4
avayaip_office
10.0:sp5
avayaip_office
10.0:sp6
avayaip_office
10.0:sp7
avayaip_office
10.1
avayaip_office
10.1:sp1
avayaip_office
10.1:sp2
𝑥
= Vulnerable software versions