CVE-2016-5285: Avaya Aura Application Enablement Services

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service.

Affected products

  • Avaya Aura Application Enablement Services: from 6.1, up to and including 6.3.3; version 7.0 only
  • Avaya Aura Application Server 5300: version 3.0 only
  • Avaya Aura Communication Manager: from 6.0, up to and including 6.3.117.0; version 7.0 only
  • Avaya Aura Communication Manager Messagint: version 7.0 only
  • Avaya Aura Conferencing: version 7.0 only; version 7.2 only; version 8.0 only
  • Avaya Aura Experience Portal: from 6.0, up to and including 7.1
  • Avaya Aura Messaging: version 6.3 only; version 6.3.3 only
  • Avaya Aura Session Manager: from 6.3, up to and including 6.3.18; version 7.0 only; version 7.0.1 only
  • Avaya Aura System Manager: from 6.3, up to and including 6.3.18; from 7.0, up to and including 7.0.1.3
  • Avaya Aura System Platform Firmware: from 6.3, up to and including 6.4.0
  • Avaya Aura Utility Services: from 6.3, up to and including 6.3.14; from 7.0, up to and including 7.0.1.2
  • Avaya Breeze Platform: from 3.0, up to and including 3.2
  • Avaya Call Management System: from 18.0.0.1, up to and including 18.0.0.2; version 17.0 only
  • Avaya CS1000E/CS1000M Signaling Server Firmware: from 7.0, up to and including 7.6
  • Avaya CS1000E Firmware: from 7.0, up to and including 7.6
  • Avaya CS1000M Firmware: from 7.0, up to and including 7.6
  • Avaya IP Office: version 8.1 only; version 9.1 only; version 10.0 only
  • Avaya Iq: version 5.2.x only
  • Avaya Meeting Exchange: version 6.2 only
  • Avaya Message Networking: from 5.2, up to and including 6.3
  • Avaya One-X Client Enablement Services: version 6.2 only
  • Avaya Proactive Contact: from 5.0, up to and including 5.1.2
  • Avaya Session Border Controller For Enterprise Firmware: from 6.2, up to and including 6.3; from 7.0, up to and including 7.1
  • Debian Debian Linux: version 8.0 only; version 9.0 only; version 10.0 only
  • Mozilla Nss: before 3.26 (fixed in 3.26)
  • and 2 more

Published 2019-11-15. Last modified 2026-06-17.