PT-2024-38374 · Avaya · Avaya Aura System Manager

Ben Leonard-Lagarde

+1

·

Published

2024-08-08

·

Updated

2025-10-01

·

CVE-2024-7480

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Avaya Aura System Manager versions 10.1.x.x through 10.2.x.x
Description An improper access control issue was found in Avaya Aura System Manager, allowing a command-line interface user with administrative privileges to read arbitrary files on the system.
Recommendations For versions 10.1.x.x through 10.2.x.x, consider restricting access to sensitive files and directories to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2024-7480

Affected Products

Avaya Aura System Manager