CVE-2007-1490

3 documents3 sources
Severity
6.0MEDIUM
EPSS
3.3%
top 12.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 16
Latest updateMay 1

Description

Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 3.1.3, and Avaya SES allow remote authenticated users to execute arbitrary commands via shell metacharacters in unspecified vectors (aka "shell command injection").

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 6.8 | Impact: 6.4

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p3jf-gpmf-rx6c: Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 32022-05-01
CVEList
CVE-2007-1490: Unspecified maintenance web pages in Avaya S87XX, S8500, and S8300 before CM 32007-03-16