Description
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32752 | An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1. |
References
| Link | Providers |
|---|---|
| https://download.avaya.com/css/public/documents/101090768 |
|
History
Tue, 21 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avaya
Avaya ip Office |
|
| CPEs | cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Avaya
Avaya ip Office |
Status: PUBLISHED
Assigner: avaya
Published:
Updated: 2024-08-01T20:33:52.976Z
Reserved: 2024-04-25T16:34:25.138Z
Link: CVE-2024-4197
Updated: 2024-08-01T20:33:52.976Z
Status : Analyzed
Published: 2024-06-25T04:15:17.007
Modified: 2025-01-21T14:31:21.327
Link: CVE-2024-4197
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD