An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
2025-06-10T06:15:22.000
2025-07-30T17:59:01.643
Analyzed
CVSSv3.1: 9.9 (CRITICAL)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | avaya | call_management_system | < 19.2.0.7 | Yes |
Application | avaya | call_management_system | < 20.0.1.0 | Yes |