CVE-2024-7480
MEDIUMAvaya Aura System Manager 10.1.x.x and 10.2.x.x - Authenticated Arbitrary File Read via CLI
Title source: llmDescription
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
References (1)
Core 1
Core References
Vendor Advisory
https://download.avaya.com/css/public/documents/101091159
Scores
CVSS v3
4.2
EPSS
0.0015
EPSS Percentile
4.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-266
Status
published
Products (2)
avaya/aura_system_manager
10.2
avaya/aura_system_manager
10.1 - 10.1.2
Published
Aug 08, 2024
Tracked Since
Feb 18, 2026