Unrestricted File Upload Vulnerability Affects Avaya IP Office
CVE-2024-4197
9.8CRITICAL
What is CVE-2024-4197?
An unrestricted file upload vulnerability exists in the One-X component of Avaya IP Office, which may permit remote attackers to execute arbitrary commands or code on the affected system. This vulnerability impacts all versions of Avaya IP Office prior to 11.1.3.1, presenting significant risks to organizations using this product. Without proper validation and restrictions on file uploads, unauthorized users may exploit this weakness to gain control over the system and perform malicious actions.
Affected Version(s)
IP Office 0