PT-2024-29663 · Avaya · Avaya Ip Office

Pear1Y

·

Published

2024-06-25

·

Updated

2025-10-01

·

CVE-2024-4196

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avaya IP Office versions prior to 11.1.3.1
Description An improper input validation issue was discovered in Avaya IP Office, allowing remote command or code execution via a specially crafted web request to the Web Control component.
Recommendations For versions prior to 11.1.3.1, update to version 11.1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Control component to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-4196

Affected Products

Avaya Ip Office