CVE-2025-1041: Avaya Call Management System RCE vulnerability
An improper input validation discovered in
Avaya Call Management System could allow an unauthorized
remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-1041?
CVE-2025-1041 is classified as a high severity vulnerability due to the potential for unauthorized remote command execution.
How do I fix CVE-2025-1041?
To fix CVE-2025-1041, upgrade to Avaya Call Management System version 19.2.0.7 or 20.0.1.0 or later.
What versions of Avaya Call Management System are affected by CVE-2025-1041?
CVE-2025-1041 affects versions 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
What type of vulnerability is CVE-2025-1041?
CVE-2025-1041 is an improper input validation vulnerability that could allow unauthorized remote commands.
What are the risks associated with CVE-2025-1041?
The risks associated with CVE-2025-1041 include potential unauthorized access and execution of arbitrary commands on the affected system.