CVE-2023-3722
19.07.2023, 20:15
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.Enginsight
Vendor | Product | Version |
---|---|---|
avaya | aura_device_services | 𝑥 ≤ 8.1.4.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration