Avaya IP Office 11.1.3.0

There are serious security vulnerabilities in Avaya IP Office. Unauthorized persons can exploit these vulnerabilities in the IP telephony software, which are classified as critical, to inject malicious code. Updates have been released to close these vulnerabilities.

Precisely crafted requests to the web control component of Avaya IP Office could lead to commands being executed or malicious code being injected from the network due to insufficient filtering of input, Avaya warns in a security advisory (CVE-2024-4196, CVSS 10, risk "critical"). Attackers can exploit a vulnerability in the One-X component that allows unlimited file uploads - this can also potentially lead to the execution of commands or malicious code from the network, as Avaya explains (CVE-2024-4197, CVSS 9.9, critical).

Updates available for Avaya

Avaya IP Office 11.1.3.0 and older versions have security vulnerabilities. Version 11.1.3.1 closes these gaps. In addition to installing the update, Avaya strongly recommends implementing best security practices such as the use of firewalls, access control lists (ACLs), physical security and appropriate access restrictions. This can minimize the impact of the security vulnerabilities. IT managers with Avaya IP Office instances should download and install the updates as soon as possible.

Current

Dial phone number
Current

Are you satisfied with your carrier support? Service at the highest level with Winet

In today's digital world, a reliable carrier service provider is essential. Carriers are the backbone of modern communications because they provide...
jamming-microsoft
Current

Microsoft with massive network disruption

Microsoft is currently experiencing a worldwide network disruption that is affecting parts of the software manufacturer's cloud services. As a result, some web services are either...
Current

Crowdstrike paralyzes security-relevant systems for hours.

Where did the disruptions occur? The most conspicuous were the difficulties in air traffic. The airport in Berlin had to be closed at...
Current

Why it's not worth importing sugar beets.

VoIP telephony from your region: refined and precisely dosed.
Current

Why you shouldn't store your apples in a Seattle store.

VoIP telephony from your region: well stored in the Swiss cloud.
Current

Why you shouldn't buy your carrots from the dealer in Washington.

VoIP telephony from your region: well-rooted, tasty, fresh.