Avaya Releases Critical Security Update for IP Office
Two critical vulnerabilities could lead to remote code execution
Summary
Two critical vulnerabilities could lead to remote code execution
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Avaya has released an advisory to address two vulnerabilities in IP Office, a unified communications platform that allows for call recording, tracking, and reporting.
- CVE-2024-4196 - CVSSv3 score of 10.0. This improper input validation vulnerability could allow an attacker to perform remote command or code execution (RCE) via a specially crafted web request to the Web Control component.
- CVE-2024-4197 - CVSSv3 score of 9.9. This unrestricted file upload vulnerability could allow an attacker to perform remote command or code execution via the One-X component.
Remediation advice
Affected organisations are encouraged to review Avaya IP Office Vulnerability advisory ASA-2024-001 and apply the relevant security update.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 25 June 2024 1:48 pm