VYPR
Medium severity6.4NVD Advisory· Published Aug 11, 2020· Updated Jun 17, 2026

CVE-2020-7029

CVE-2020-7029

Description

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • cpe:2.3:a:avaya:aura_communication_manager:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:avaya:aura_communication_manager:*:*:*:*:*:*:*:*range: >=7.0,<=7.1.3.4
    • (no CPE)range: 7.0.x, 7.1.x prior to 7.1.3.5, 8.0.x
    • (no CPE)range: 8.0.x
  • cpe:2.3:a:avaya:aura_messaging:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:avaya:aura_messaging:*:*:*:*:*:*:*:*range: >=7.0,<7.1
    • cpe:2.3:a:avaya:aura_messaging:7.1:-:*:*:*:*:*:*
    • cpe:2.3:a:avaya:aura_messaging:7.1:sp1:*:*:*:*:*:*
    • (no CPE)range: 7.0.x, 7.1 and 7.1 SP1
    • (no CPE)range: 7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.