PT-2024-29663 · Avaya · Avaya Ip Office
Pear1Y
·
Published
2024-06-25
·
Updated
2025-10-01
·
CVE-2024-4196
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avaya IP Office versions prior to 11.1.3.1
Description
An improper input validation issue was discovered in Avaya IP Office, allowing remote command or code execution via a specially crafted web request to the Web Control component.
Recommendations
For versions prior to 11.1.3.1, update to version 11.1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Control component to minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Avaya Ip Office