Unrestricted File Upload Vulnerability Affects Avaya IP Office
CVE-2024-4197
9.8CRITICAL
Summary
An unrestricted file upload vulnerability exists in the One-X component of Avaya IP Office, which may permit remote attackers to execute arbitrary commands or code on the affected system. This vulnerability impacts all versions of Avaya IP Office prior to 11.1.3.1, presenting significant risks to organizations using this product. Without proper validation and restrictions on file uploads, unauthorized users may exploit this weakness to gain control over the system and perform malicious actions.
Affected Version(s)
IP Office 0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved