First published: Tue Jun 25 2024(Updated: )
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
Credit: securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
<11.1.3.1 | ||
Avaya IP Office | <11.1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4197 is considered a critical security vulnerability due to its potential for remote command or code execution.
To mitigate CVE-2024-4197, upgrade Avaya IP Office to version 11.1.3.1 or later.
CVE-2024-4197 affects the One-X component of Avaya IP Office software.
Yes, CVE-2024-4197 could potentially lead to unauthorized access and data breaches.
No official workarounds are recommended for CVE-2024-4197; upgrading is strongly advised.