CVE-2020-7030
04.06.2020, 00:15
A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.Enginsight
Vendor | Product | Version |
---|---|---|
avaya | ip_office | 10.0 ≤ 𝑥 ≤ 10.1.0.7 |
avaya | ip_office | 11.0 ≤ 𝑥 ≤ 11.0.4.2 |
avaya | ip_office | 9.0 |
avaya | ip_office | 9.0:sp1 |
avaya | ip_office | 9.0:sp10 |
avaya | ip_office | 9.0:sp11 |
avaya | ip_office | 9.0:sp12 |
avaya | ip_office | 9.0:sp2 |
avaya | ip_office | 9.0:sp3 |
avaya | ip_office | 9.0:sp4 |
avaya | ip_office | 9.0:sp5 |
avaya | ip_office | 9.0:sp6 |
avaya | ip_office | 9.0:sp7 |
avaya | ip_office | 9.0:sp8 |
avaya | ip_office | 9.0:sp9 |
avaya | ip_office | 9.1 |
avaya | ip_office | 9.1:sp1 |
avaya | ip_office | 9.1:sp10 |
avaya | ip_office | 9.1:sp11 |
avaya | ip_office | 9.1:sp12 |
avaya | ip_office | 9.1:sp3 |
avaya | ip_office | 9.1:sp4 |
avaya | ip_office | 9.1:sp5 |
avaya | ip_office | 9.1:sp6 |
avaya | ip_office | 9.1:sp7 |
avaya | ip_office | 9.1:sp8 |
avaya | ip_office | 9.1:sp9 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-522 - Insufficiently Protected CredentialsThe product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
References