First published: Fri Mar 16 2007(Updated: )
Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura Communication Manager | <=3.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1490 is classified as a critical vulnerability due to the potential for remote command execution.
The best way to mitigate CVE-2007-1490 is to upgrade to Avaya Communication Manager version 3.1.4 or later.
CVE-2007-1490 affects users of Avaya S87XX, S8500, and S8300 systems running versions prior to CM 3.1.3.
The implications of CVE-2007-1490 include unauthorized remote command execution, which can lead to data breaches and system compromise.
No, CVE-2007-1490 can be exploited by authenticated users, making authentication alone insufficient as a defense.