Vulnerability Description
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Call Management System | >= 18.0.0.1, < 19.2.0.7 |
Related Weaknesses (CWE)
References
- https://support.avaya.com/css/public/documents/101093084Vendor Advisory
FAQ
What is CVE-2025-1041?
CVE-2025-1041 is a vulnerability with a CVSS score of 9.9 (CRITICAL). An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior t...
How severe is CVE-2025-1041?
CVE-2025-1041 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-1041?
Check the references section above for vendor advisories and patch information. Affected products include: Avaya Call Management System.