Skip to main content

Avaya Releases Critical Security Update for IP Office

Two critical vulnerabilities could lead to remote code execution

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Two critical vulnerabilities could lead to remote code execution


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Avaya has released an advisory to address two vulnerabilities in IP Office, a unified communications platform that allows for call recording, tracking, and reporting.

  • CVE-2024-4196 - CVSSv3 score of 10.0. This improper input validation vulnerability could allow an attacker to perform remote command or code execution (RCE) via a specially crafted web request to the Web Control component.
  • CVE-2024-4197 - CVSSv3 score of 9.9. This unrestricted file upload vulnerability could allow an attacker to perform remote command or code execution via the One-X component. 

Remediation advice

Affected organisations are encouraged to review Avaya IP Office Vulnerability advisory ASA-2024-001 and apply the relevant security update. 



Last edited: 25 June 2024 1:48 pm