CVE-2025-1041

An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:*
cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:*

History

30 Jul 2025, 17:59

Type Values Removed Values Added
CPE cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:*
First Time Avaya
Avaya call Management System
References () https://support.avaya.com/css/public/documents/101093084 - () https://support.avaya.com/css/public/documents/101093084 - Vendor Advisory

12 Jun 2025, 16:06

Type Values Removed Values Added
Summary
  • (es) Una validación de entrada incorrecta detectada en Avaya Call Management System podría permitir un comando remoto no autorizado mediante una solicitud web especialmente manipulada. Las versiones afectadas incluyen la 18.x, la 19.x anterior a la 19.2.0.7 y la 20.x anterior a la 20.0.1.0.

10 Jun 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-10 06:15

Updated : 2025-07-30 17:59


NVD link : CVE-2025-1041

Mitre link : CVE-2025-1041

CVE.ORG link : CVE-2025-1041


JSON object : View

Products Affected

avaya

  • call_management_system
CWE
CWE-20

Improper Input Validation