Apply the Avaya IP Office patch now due to critical security vulnerabilities

There are serious security vulnerabilities in Avaya IP Office. Unauthorized users can exploit these vulnerabilities—which are classified as critical—in the IP telephony software to inject malicious code. Updates have been released to address these vulnerabilities.
Avaya warns in a security advisory (CVE-2024-4196, CVSS 10, risk level «critical»). In the One-X component, attackers can exploit a vulnerability that allows unlimited file uploads—which could also potentially lead to the execution of commands or malicious code from the network, as Avaya explains (CVE-2024-4197, CVSS 9.9, critical).
Updates Available for Avaya
Avaya IP Office 11.1.3.0 and earlier versions contain security vulnerabilities. Version 11.1.3.1 addresses these vulnerabilities. In addition to installing the update, Avaya strongly recommends implementing best security practices, such as using firewalls, access control lists (ACLs), physical security measures, and appropriate access restrictions. This will help minimize the impact of the security vulnerabilities. IT administrators with Avaya IP Office installations should download and install the updates as soon as possible.
