An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://download.avaya.com/css/public/documents/101091159 |     | 
History
                    Wed, 01 Oct 2025 02:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-269 | 
Wed, 01 Oct 2025 02:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-266 | 
Wed, 11 Sep 2024 15:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Avaya Avaya aura System Manager | |
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:avaya:aura_system_manager:*:*:*:*:*:*:*:* cpe:2.3:a:avaya:aura_system_manager:10.2:*:*:*:*:*:*:* | |
| Vendors & Products | Avaya Avaya aura System Manager | 
Thu, 08 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Thu, 08 Aug 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support. | |
| Title | Improper access control in Avaya Aura System Manager | |
| Weaknesses | CWE-269 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: avaya
Published: 2024-08-08T16:04:25.989Z
Updated: 2025-10-01T01:33:36.494Z
Reserved: 2024-08-05T08:33:54.944Z
Link: CVE-2024-7480
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-08T18:38:07.162Z
 NVD
                        NVD
                    Status : Modified
Published: 2024-08-08T16:15:09.567
Modified: 2025-10-01T02:15:33.437
Link: CVE-2024-7480
 Redhat
                        Redhat
                    No data.
 ReportizFlow
ReportizFlow