Improper Input Validation in Avaya Call Management System
CVE-2025-1041
9.8CRITICAL
What is CVE-2025-1041?
An improper input validation vulnerability in the Avaya Call Management System could be exploited by an attacker to execute unauthorized remote commands. This issue is triggered by specially crafted web requests, which take advantage of the insufficient validation mechanisms in the software. Users operating on affected versions 18.x, 19.x before 19.2.0.7, and 20.x before 20.0.1.0 should be aware of this risk and apply the necessary security updates to mitigate potential threats.
Affected Version(s)
Avaya Call Management System 18.0 < 19.2.0.7
Avaya Call Management System 20.0 < 20.0.1.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Roberto Olivero
Juan Ignacio Elola