First published: Wed Jul 19 2023(Updated: )
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Credit: securityalerts@avaya.com securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura Device Services | <=8.1.4.0 |
Upgrade to 8.1.4.1 or the latest supported version of Avaya Aura Device Services.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-3722 is an OS command injection vulnerability found in the Avaya Aura Device Services Web application.
CVE-2023-3722 could allow remote code execution as the Web server user via a malicious uploaded file, potentially leading to unauthorized access and control of the affected system.
Avaya Aura Device Services version 8.1.4.0 and earlier are affected by CVE-2023-3722.
CVE-2023-3722 has a severity rating of 9.8 (critical).
Yes, it is recommended to upgrade to a version later than 8.1.4.0 to mitigate the vulnerability. Please refer to the vendor's advisory for detailed instructions.