CVE-2023-3722
Last modified
CVE-2023-3722 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.. EPSS estimates a 3.33% chance of exploitation in the next 30 days.
Description
An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Aura Device Services | <= 8.1.4.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3722?
How severe is CVE-2023-3722?
How do I fix CVE-2023-3722?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-37214 Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.0…9.8
- CVE-2023-37215 JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Cre…9.8
- CVE-2023-37216 AnaSystem SensMini M4 – Using the configuration tool, a…6.5
- CVE-2023-37217 Tadiran Telecom Aeonix - CWE-204: Observable Response Discr…5.3
- CVE-2023-37218 Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pa…7.5
- CVE-2023-37219 Tadiran Telecom Composit - CWE-1236: Improper Neutralizatio…7.8
- CVE-2023-37220 Synel Terminals - CWE-494: Download of Code Without Integri…9.8
- CVE-2023-37221 7Twenty BOT - CWE-79: Improper Neutralization of Input Duri…6.1
- CVE-2023-37222 Farsight Tech Nordic AB ProVide version 14.5 - Multiple…4.8
- CVE-2023-37223Cross Site Scripting (XSS) vulnerability in Archer Platform …5.4
- CVE-2023-37224An issue in Archer Platform before v.6.13 fixed in v.6.12.0.…5.5
- CVE-2023-37225Pexip Infinity before 32 allows Webapp1 XSS via preconfigure…6.1
Are you affected by CVE-2023-3722?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
