CVE-2016-2783
Avaya VOSS 4.1.0.0 SPB Traffic Traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.
Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) en versiones anteriores a 4.2.3.0 y 5.x en versiones anteriores a 5.0.1.0 no maneja adecuadamente los índices VLAN e I-SIS, lo que permite a atacantes remotos obtener acceso no autorizado a través de marcos Ethernet manipulados.
Avaya Fabric Connect VSP, under specific conditions, can accept and process specially crafted and spoofed Ethernet frames, which can lead to unauthorized access to devices intended to be secured from untrusted traffic sources. The vulnerability is caused by mishandling VLAN and I-SID indexes within the Fabric infrastructure. Version 4.1.0.0 is affected.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-02-28 CVE Reserved
- 2016-07-28 CVE Published
- 2020-12-22 First Exploit
- 2024-08-05 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-19: Data Processing Errors
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/92157 | Vdb Entry | |
https://packetstormsecurity.com/files/138082/Avaya-VOSS-4.1.0.0-SPB-Traffic-Traversal.html | X_refsource_misc |
|
URL | Date | SRC |
---|---|---|
https://github.com/iknowjason/spb | 2020-12-22 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Avaya Search vendor "Avaya" | Vsp Operating System Software Search vendor "Avaya" for product "Vsp Operating System Software" | <= 4.2.2.0 Search vendor "Avaya" for product "Vsp Operating System Software" and version " <= 4.2.2.0" | - |
Affected
| ||||||
Avaya Search vendor "Avaya" | Vsp Operating System Software Search vendor "Avaya" for product "Vsp Operating System Software" | 5.0.0.0 Search vendor "Avaya" for product "Vsp Operating System Software" and version "5.0.0.0" | - |
Affected
|