vendor:
Avaya IP Office
by:
hyp3rlinx
7.5
CVSS
HIGH
Insecure Transit Password Disclosure
200
CWE
Product Name: Avaya IP Office
Affected Version From: v9.1.8.0
Affected Version To: 11
Patch Exists: YES
Related CWE: CVE-2020-7030
CPE: a:avaya:ip_office:9.1.8.0
Platforms Tested:
2020
Avaya IP Office 11 – Password Disclosure
A sensitive information disclosure vulnerability exists in the web interface component of Avaya IP Office. A local user can gain unauthorized access to the component by exploiting the Base64 encoded credentials passed in the URL query string.
Mitigation:
To mitigate this vulnerability, Avaya recommends restricting access to the IP Office web interface and implementing strong password policies. Additionally, ensure that the system is updated with the latest patches and security updates.