CVE-2016-2783: Critical severity Avaya Vsp Operating System Software vulnerability
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-2783?
CVE-2016-2783 has a medium severity rating due to the potential for unauthorized access through crafted Ethernet frames.
How do I fix CVE-2016-2783?
To fix CVE-2016-2783, update the Avaya Fabric Connect Virtual Services Platform Operating System Software to version 4.2.3.0 or later, or 5.0.1.0 or later.
What types of devices are affected by CVE-2016-2783?
CVE-2016-2783 affects the Avaya Fabric Connect Virtual Services Platform Operating System Software versions prior to 4.2.3.0 and 5.0.1.0.
What vulnerabilities does CVE-2016-2783 exploit?
CVE-2016-2783 exploits improper handling of VLAN and I-SIS indexes to allow remote attackers unauthorized access.
Who can be impacted by CVE-2016-2783?
Organizations using vulnerable versions of Avaya VSP Operating System Software can be impacted by CVE-2016-2783.