CVE-2024-4197: Avaya IP Office One-X Portal File Upload Vulnerability
An unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component. Affected versions include all versions prior to 11.1.3.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Avaya IP Office One-X Portalto a version that resolves this vulnerability.Fixed in 11.1.3.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4197?
CVE-2024-4197 is considered a critical security vulnerability due to its potential for remote command or code execution.
How do I fix CVE-2024-4197?
To mitigate CVE-2024-4197, upgrade Avaya IP Office to version 11.1.3.1 or later.
What components are affected by CVE-2024-4197?
CVE-2024-4197 affects the One-X component of Avaya IP Office software.
Can CVE-2024-4197 lead to data breaches?
Yes, CVE-2024-4197 could potentially lead to unauthorized access and data breaches.
Is there a workaround for CVE-2024-4197 if I cannot upgrade immediately?
No official workarounds are recommended for CVE-2024-4197; upgrading is strongly advised.