Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Rahul Singh

Researcher fromCOMSEC Global
#28779of 53,635
8.8Total CVSS
Vulnerabilities · 1
PT-2020-19346
8.8
2020-08-11
Avaya · Avaya Aura Messaging · CVE-2020-7029
**Name of the Vulnerable Software and Affected Versions** Avaya Aura Communication Manager versions 7.0.x, 7.1.x through 7.1.3.4, 8.0.x Avaya Aura Messaging versions 7.0.x, 7.1, 7.1 SP1 **Description** A Cross-Site Request Forgery (CSRF) issue was found in the System Management Interface Web component. This could allow an unauthenticated remote attacker to perform Web administration actions with the privileges of the authenticated user. **Recommendations** For Avaya Aura Communication Manager versions 7.0.x, 7.1.x through 7.1.3.4, 8.0.x, update to version 7.1.3.5 or later to resolve the issue. For Avaya Aura Messaging versions 7.0.x, 7.1, 7.1 SP1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.