An improper input validation discovered in 
Avaya Call Management System
could allow an unauthorized 
remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
                
            References
                    | Link | Resource | 
|---|---|
| https://support.avaya.com/css/public/documents/101093084 | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    30 Jul 2025, 17:59
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:* | |
| First Time | Avaya Avaya call Management System | |
| References | () https://support.avaya.com/css/public/documents/101093084 - Vendor Advisory | 
12 Jun 2025, 16:06
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
10 Jun 2025, 06:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-10 06:15
Updated : 2025-07-30 17:59
NVD link : CVE-2025-1041
Mitre link : CVE-2025-1041
CVE.ORG link : CVE-2025-1041
JSON object : View
Products Affected
                avaya
- call_management_system
CWE
                
                    
                        
                        CWE-20
                        
            Improper Input Validation
