CVE-2020-7038: Avaya Meetings Server Information Disclosure vulnerability
A vulnerability was discovered in Management component of Avaya Equinox Conferencing that could potentially allow an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions. The affected versions of Management component of Avaya Equinox Conferencing include all 3.x versions before 3.17. Avaya Equinox Conferencing is now offered as Avaya Meetings Server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Avaya Equinox Conferencing vulnerability?
The vulnerability ID for this Avaya Equinox Conferencing vulnerability is CVE-2020-7038.
What is the severity of CVE-2020-7038?
The severity of CVE-2020-7038 is high with a CVSS score of 7.5.
How does this vulnerability affect Avaya Equinox Conferencing?
This vulnerability affects the Management component of Avaya Equinox Conferencing, allowing an unauthenticated, remote attacker to gain access to screen sharing and whiteboard sessions.
Which versions of Avaya Equinox Conferencing are affected by this vulnerability?
All versions of the Management component of Avaya Equinox Conferencing 3.x up to and including 9.1.11 are affected by this vulnerability.
Is there a fix available for CVE-2020-7038?
Yes, Avaya has released a fix for this vulnerability. Please refer to the Avaya support website for more information.