Vulnerabilities (CVE)

Filtered by vendor Avaya Subscribe
Filtered by product Aura Device Services
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-3722 1 Avaya 1 Aura Device Services 2023-12-10 N/A 9.8 CRITICAL
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
CVE-2021-25654 1 Avaya 1 Aura Device Services 2023-12-10 4.6 MEDIUM 7.8 HIGH
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.