Improper Input Validation in Avaya Call Management System
CVE-2025-1041

9.9CRITICAL

Key Information:

Vendor

Avaya

Vendor
CVE Published:
10 June 2025

What is CVE-2025-1041?

An improper input validation vulnerability in the Avaya Call Management System could be exploited by an attacker to execute unauthorized remote commands. This issue is triggered by specially crafted web requests, which take advantage of the insufficient validation mechanisms in the software. Users operating on affected versions 18.x, 19.x before 19.2.0.7, and 20.x before 20.0.1.0 should be aware of this risk and apply the necessary security updates to mitigate potential threats.

Affected Version(s)

Avaya Call Management System 18.0 < 19.2.0.7

Avaya Call Management System 20.0 < 20.0.1.0

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Roberto Olivero
Juan Ignacio Elola
.
CVE-2025-1041 : Improper Input Validation in Avaya Call Management System