« Volver al listado

CVE-2017-12969

Estado: ModificadaAlta (8.8)—

Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-12969",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-11-10T02:29:17.637",
  "references": [
    {
      "url": "http://downloads.avaya.com/css/P8/documents/101044091",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2017/Nov/17",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/101667",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/43120/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://downloads.avaya.com/css/P8/documents/101044091",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://hyp3rlinx.altervista.org/advisories/AVAYA-OFFICE-IP-%28IPO%29-v9.1.0-10.1-VIEWERCTRL-ACTIVE-X-BUFFER-OVERFLOW-0DAY.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://packetstormsecurity.com/files/144882/Avaya-IP-Office-IPO-10.1-Active-X-Buffer-Overflow.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2017/Nov/17",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/101667",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/43120/",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in the ViewerCtrlLib.ViewerCtrl ActiveX control in Avaya IP Office Contact Center before 10.1.1 allows remote attackers to cause a denial of service (heap corruption and crash) or execute arbitrary code via a long string to the open method."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en el control ViewerCtrlLib.ViewerCtrl de ActiveX en Avaya IP Office Contact Center, en versiones anteriores a la 10.1.1, permite que atacantes remotos provoquen una denegación de servicio (corrupción de memoria dinámica o heap y cierre inesperado) o ejecuten código arbitrario mediante una cadena larga para el método open."
    }
  ],
  "lastModified": "2026-06-17T01:04:14.057",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1:sp11:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D59361D7-B017-4CE2-81A5-291C53CC0E65"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C5C2AE6-BC1B-4448-8CCE-4F282A4C6959"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.0.2209.1540:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D46DB486-88EC-49F3-AA9E-3E8755D61AF6"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1ADE5F08-A329-4083-A02A-BA3447F32991"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DA0E24C0-8DAF-4199-A18A-625B50CA9369"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6BA134E8-52E4-4CD9-9ABF-C5A6F9E5C272"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:9.1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2C5575DC-1A36-40AE-9A98-480C5A7C8BD8"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:10.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "203590C4-9B69-470B-8BF5-E436CE680A86"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:10.0.0.3-8600.1705:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "912179E1-137C-4DEC-A915-CF4BDD5AE11E"
            },
            {
              "criteria": "cpe:2.3:a:avaya:ip_office_contact_center:10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54AE4793-6525-4BCD-8883-681406784F39"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}