Lucene search

K
cve[email protected]CVE-2019-7000
HistoryJul 31, 2019 - 10:15 p.m.

CVE-2019-7000

2019-07-3122:15:13
CWE-79
web.nvd.nist.gov
59
cve-2019-7000
cross-site scripting
xss
avaya aura conferencing
web ui
code execution
information disclosure
vulnerability
nvd

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

38.2%

A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.

Affected configurations

NVD
Node
avayaaura_conferencingRange8.0
OR
avayaaura_conferencingMatch8.0-
OR
avayaaura_conferencingMatch8.0sp10
OR
avayaaura_conferencingMatch8.0sp11
OR
avayaaura_conferencingMatch8.0sp12
OR
avayaaura_conferencingMatch8.0sp13
OR
avayaaura_conferencingMatch8.0sp2
OR
avayaaura_conferencingMatch8.0sp4
OR
avayaaura_conferencingMatch8.0sp5
OR
avayaaura_conferencingMatch8.0sp7
OR
avayaaura_conferencingMatch8.0sp8

CNA Affected

[
  {
    "product": "Avaya Aura Conferencing",
    "vendor": "Avaya",
    "versions": [
      {
        "lessThan": "8.0.14",
        "status": "affected",
        "version": "8.x",
        "versionType": "custom"
      }
    ]
  }
]

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

0.001 Low

EPSS

Percentile

38.2%

Related for CVE-2019-7000