← Vulnerability feed

Vulnerability record · CVE-2018-15610 · published 12 September 2018

CVE-2018-15610: Avaya ip office improper access control vulnerability

Avaya · Ip Office

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

8.8 CVSS 3.0 High EPSS 1.8% · top 21.8% CWE-284 · Improper access controlCWE-22 · Path traversal
8.8CVSS 3.0 base score, v2 9.0
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. Affected versions of Avaya IP Office include 9.1 through 9.1 SP12, 10.0 through 10.0 SP7, and 10.1 through 10.1 SP2.

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-15610 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4197Avaya ip office unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…EPSS 0.78%9.8CVE-2024-4196Avaya ip office vulnerabilityAn improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafte…EPSS 0.59%9.6CVE-2017-11309Avaya ip office memory buffer overflow vulnerabilityBuffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.EPSS 9.4%7.8CVE-2021-25657Avaya ip office improper privilege management vulnerabilityA privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate…EPSS 0.26%7.5CVE-2019-7005Avaya ip office information exposure vulnerabilityA vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc…EPSS 1.2%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%5.5CVE-2020-7030Avaya ip office insufficiently protected credentials vulnerabilityA sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…EPSS 1.0%5.4CVE-2018-15614Avaya ip office cross-site scripting vulnerabilityA vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via field…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2018-15610), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.