Back to Database
Status published
Medium
CVE-2023-31187
Avaya IX Workforce Engagement - CWE-522: Insufficiently Protected Credentials
Vulnerability Description
Avaya IX Workforce Engagement v15.2.7.1195 - CWE-522: Insufficiently Protected Credentials
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-31187
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Dudu Moyal, Gad Abuhatziera, Moriel Harush
More from Avaya
View All →CVE-2025-1041
Avaya Call Management System RCE vulnerability
Critical
9.9
CVE-2024-7480
Improper access control in Avaya Aura System Manager
Medium
4.2
CVE-2024-7477
Avaya Aura System Manager SQL injection vulnerability
Medium
6.5
CVE-2024-4197
Avaya IP Office One-X Portal File Upload Vulnerability
Critical
9.9
CVE-2024-4196
Avaya IP Office Web Control RCE Vulnerability
Critical
10
Affected Vendor
Avaya
View all reports →Affected Software
IX Workforce Engagement
Vulnerable Versions:
Update to the latest version
Timeline
Official Publish:
May 30th, 2023
Last Modified:
January 10th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N