Avaya Call Management System
cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*
- ~18
- ~19.2.0.6
- ~20.0
- ~20.0.0
A remote command execution vulnerability has been identified in Avaya Call Management System (CMS) versions 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0. The vulnerability arises from improper input validation, which could allow an unauthorized remote command to be executed via a specially crafted web request.
Exploitation of this vulnerability could lead to unauthorized remote command execution on the affected system.
Users of Avaya CMS are advised to upgrade to version 19.2.0.7 or later if they are on a version from 18.x to 19.2.0.6. For those on version 20.0 to 20.0.0.x, upgrading to 20.0.1.0 or later is recommended.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.