PT-2024-29669 · Avaya · Avaya Ip Office
Pear1Y
·
Published
2024-06-25
·
Updated
2025-01-21
·
CVE-2024-4197
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Avaya IP Office versions prior to 11.1.3.1
Description
An unrestricted file upload issue in Avaya IP Office was discovered, which could allow remote command or code execution via the One-X component.
Recommendations
For versions prior to 11.1.3.1, update to version 11.1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the One-X component to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avaya Ip Office