High severity8.6NVD Advisory· Published Jul 19, 2023· Updated Jun 17, 2026
CVE-2023-3722
CVE-2023-3722
Description
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Affected products
3cpe:2.3:a:avaya:aura_device_services:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:avaya:aura_device_services:*:*:*:*:*:*:*:*range: <=8.1.4.0
- (no CPE)range: <=8.1.4.0
- Range: 0
Patches
Vulnerability mechanics
References
1- download.avaya.com/css/public/documents/101076366nvdRelease Notes
News mentions
0No linked articles in our index yet.