An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Advisories
No advisories yet.
Fixes
Solution
Upgrade to 8.1.4.1 or the latest supported version of Avaya Aura Device Services.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://download.avaya.com/css/public/documents/101076366 |
|
History
Tue, 22 Oct 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: avaya
Published:
Updated: 2024-10-22T19:17:58.386Z
Reserved: 2023-07-17T19:33:59.907Z
Link: CVE-2023-3722
Updated: 2024-08-02T07:01:57.364Z
Status : Modified
Published: 2023-07-19T20:15:11.020
Modified: 2024-11-21T08:17:55.113
Link: CVE-2023-3722
No data.
OpenCVE Enrichment
No data.
Weaknesses