Description
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-32751 | An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1. |
References
| Link | Providers |
|---|---|
| https://download.avaya.com/css/public/documents/101090768 |
|
History
Wed, 01 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 |
Wed, 01 Oct 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 01 Oct 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-782 |
Tue, 21 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Avaya
Avaya ip Office |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Avaya
Avaya ip Office |
Status: PUBLISHED
Assigner: avaya
Published:
Updated: 2025-10-01T01:32:20.651Z
Reserved: 2024-04-25T16:34:11.466Z
Link: CVE-2024-4196
Updated: 2024-08-01T20:33:52.951Z
Status : Modified
Published: 2024-06-25T04:15:16.580
Modified: 2025-10-01T02:15:33.260
Link: CVE-2024-4196
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD