CVE-2020-7030

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
04/06/2020
Last modified:
09/06/2020

Description

A sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user to gain unauthorized access to the component. Affected versions of IP Office include: 9.x, 10.0 through 10.1.0.7 and 11.0 though 11.0.4.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:* 10.0 (including) 10.1.0.7 (including)
cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:* 11.0 (including) 11.0.4.2 (including)
cpe:2.3:a:avaya:ip_office:9.0:-:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp1:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp10:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp11:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp12:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp2:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp3:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp4:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp5:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp6:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp7:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp8:*:*:*:*:*:*
cpe:2.3:a:avaya:ip_office:9.0:sp9:*:*:*:*:*:*