← Vulnerability feed

Vulnerability record · CVE-2017-11309 · published 10 November 2017

CVE-2017-11309: Avaya ip office memory buffer overflow vulnerability

Avaya · Ip Office

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

9.6 CVSS 3.0 Critical EPSS 9.4% · top 4.8% CWE-119 · Memory buffer overflow
9.6CVSS 3.0 base score, v2 6.8
9.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Buffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11309 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4197Avaya ip office unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…EPSS 0.78%9.8CVE-2024-4196Avaya ip office vulnerabilityAn improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafte…EPSS 0.59%8.8CVE-2018-15610Avaya ip office improper access control vulnerabilityA vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A…EPSS 1.8%7.8CVE-2021-25657Avaya ip office improper privilege management vulnerabilityA privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate…EPSS 0.26%7.5CVE-2019-7005Avaya ip office information exposure vulnerabilityA vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc…EPSS 1.2%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%5.5CVE-2020-7030Avaya ip office insufficiently protected credentials vulnerabilityA sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…EPSS 1.0%5.4CVE-2018-15614Avaya ip office cross-site scripting vulnerabilityA vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via field…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2017-11309), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.