Record summary

CVE-2023-3722 has a selected CVSS score of 8.6 (high); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 17, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Repository PoCs
1
Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 22, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

CVE List, VulnCheckBefore 8.1.4.1affected

Proofs of concept

1

Repository PoCs

GitHubpizza-power/CVE-2023-3722Repository PoCby pizza-powerStars: 2Not analyzed2 files

3.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHAvaya Aura Device Services - OS Command InjectionCVSS 8.6

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

Impact

Unauthenticated attackers can upload malicious PHP files to execute arbitrary code with web server privileges on Avaya Aura Device Services, potentially compromising VoIP infrastructure and accessing telecommunications data.

Remediation

Update Avaya Aura Device Services to a version newer than 8.1.4.0 that validates uploaded files and restricts code execution in the PhoneBackup directory.

WeaknessesCWE-434
Authorsiamnoooob, pdresearch
Template tagscvecve2023avayarceuploaddeviceservicesintrusivevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CPE: cpe:2.3:a:avaya:aura_device_services:*:*:*:*:*:*:*:*
Shodan: html:"Avaya Aura® Utility Services"
FOFA: body="Avaya Aura® Utility Services"

Source: ProjectDiscovery

References

2