Skip to content

CVE-2023-3722 | Aura Device Services

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier..This CVE has a CVSS3.1 score of 8.6 and a Base Severity of HIGH.

InfoDetails
CVE IDCVE-2023-3722
CVE StatePUBLISHED
BaseScore8.6
BaseSeverityHIGH
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
VersionNA

References for CVE-2023-3722 :
https://download.avaya.com/css/public/documents/101076366

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)HIGH
Integrity(I)LOW