PT-2024-29663 · Avaya · Avaya Ip Office

·

CVE-2024-4196

·

Published

2024-06-25

·

Updated

2025-10-01

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avaya IP Office versions prior to 11.1.3.1
Description An improper input validation issue was discovered in Avaya IP Office, allowing remote command or code execution via a specially crafted web request to the Web Control component.
Recommendations For versions prior to 11.1.3.1, update to version 11.1.3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Control component to minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4196

Affected Products

Avaya Ip Office