← Vulnerability feed

Vulnerability record · CVE-2024-7480 · published 8 August 2024

CVE-2024-7480: Avaya aura system manager vulnerability

Avaya · Aura System Manager

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

4.4 CVSS 3.1 Medium EPSS 0.15% · top 96.4% CWE-266 · CWE-266
4.4CVSS 3.1 base score
0.15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2010-2943Linux kernel information exposure vulnerabilityThe xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote a…EPSS 17%7.8CVE-2010-2492Linux kernel classic buffer overflow vulnerabilityBuffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow loc…EPSS 0.43%7.8CVE-2010-2798Linux kernel null pointer dereference vulnerabilityThe gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with s…EPSS 0.41%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%7.1CVE-2009-3939Linux kernel incorrect permission assignment vulnerabilityThe poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users t…EPSS 0.44%6.7CVE-2024-7477Avaya aura system manager sql injection vulnerabilityA SQL injection vulnerability was found which could allow a command line interface (CLI) user with administrative privileges to execute arbitrary que…EPSS 0.19%6.5CVE-2020-7032Avaya aura system manager xml external entity (xxe) vulnerabilityAn XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side r…EPSS 2.9%5.5CVE-2010-2942Linux kernel memory leak vulnerabilityThe actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2024-7480), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.