CVE-2025-1041 Details
Description
An improper input validation discovered in Avaya Call Management System could allow an unauthorized remote command via a specially crafted web request. Affected versions include 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0.
A remote command execution vulnerability has been identified in Avaya Call Management System (CMS) versions 18.x, 19.x prior to 19.2.0.7, and 20.x prior to 20.0.1.0. The vulnerability arises from improper input validation, which could allow an unauthorized remote command to be executed via a specially crafted web request.
Users of Avaya CMS are advised to upgrade to version 19.2.0.7 or later if they are on a version from 18.x to 19.2.0.6. For those on version 20.0 to 20.0.0.x, upgrading to 20.0.1.0 or later is recommended.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.avaya.com/css/public/documents/101093084 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| avaya call management system | >= 18.0.0.1, < 19.2.0.7 >= 20.0, < 20.0.1.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2025 | Initial Analysis | [email protected] |
| Jun 10, 2025 | New CVE Received | [email protected] |