CVE-2020-7029 - CVE House
Back to Database
Status published Medium CVE-2020-7029

Avaya Product System Management Interface Cross-Site Request Forgery Vulnerability

Vulnerability Description

A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This vulnerability could allow an unauthenticated remote attacker to perform Web administration actions with the privileged level of the authenticated user. Affected versions of Communication Manager are 7.0.x, 7.1.x prior to 7.1.3.5 and 8.0.x. Affected versions of Messaging are 7.0.x, 7.1 and 7.1 SP1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-7029

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Avaya Aura Communication Manager, Avaya Aura Messaging
Vulnerable Versions:
8.0.x, 7.0

Timeline

Official Publish: August 11th, 2020
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L

Weaknesses (CWE)