CVE-2016-2783: Avaya Vsp Operating System Software

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

Avaya Fabric Connect Virtual Services Platform (VSP) Operating System Software (VOSS) before 4.2.3.0 and 5.x before 5.0.1.0 does not properly handle VLAN and I-SIS indexes, which allows remote attackers to obtain unauthorized access via crafted Ethernet frames.

Affected products

  • Avaya Vsp Operating System Software: up to and including 4.2.2.0; version 5.0.0.0 only

Published 2017-01-23. Last modified 2026-06-17.