CVE-2025-1041

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/06/2025
Last modified:
30/07/2025

Description

An improper input validation discovered in <br /> <br /> Avaya Call Management System<br /> could allow an unauthorized <br /> <br /> remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:* 18.0.0.1 (including) 19.2.0.7 (excluding)
cpe:2.3:a:avaya:call_management_system:*:*:*:*:*:*:*:* 20.0 (including) 20.0.1.0 (excluding)


References to Advisories, Solutions, and Tools