CVE-2023-3722
Avaya Aura Device Services Remote Code Execution
Record summary
CVE-2023-3722 has a selected CVSS score of 8.6 (high); EIP currently links 1 repository PoC and 1 Nuclei template.
Description
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 17, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Aura Device ServicesBrowse Avaya / Aura Device ServicesDefault status: affected | CVE List, VulnCheck | Before 8.1.4.1 | affected |
Proofs of concept
1Repository PoCs
GitHubpizza-power/CVE-2023-3722Repository PoCby pizza-powerStars: 2Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHAvaya Aura Device Services - OS Command InjectionCVSS 8.6
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Impact
Unauthenticated attackers can upload malicious PHP files to execute arbitrary code with web server privileges on Avaya Aura Device Services, potentially compromising VoIP infrastructure and accessing telecommunications data.
Remediation
Update Avaya Aura Device Services to a version newer than 8.1.4.0 that validates uploaded files and restricts code execution in the PhoneBackup directory.
Source: ProjectDiscovery