CVE-2020-7034 – Command injection in Avaya Session Border Controller for Enterprise
https://notcve.org/view.php?id=CVE-2020-7034
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affected versions of Avaya Session Border Controller for Enterprise include 7.x, 8.0 through 8.1.1.x Una vulnerabilidad de inyección de comandos en Avaya Session Border Controller for Enterprise, podría permitir a un atacante remoto autenticado enviar mensajes especialmente diseñados y ejecutar comandos arbitrarios con los privilegios del sistema afectado. Las versiones afectadas de Avaya Session Border Controller for Enterprise incluyen versiones 7.x, 8.0 hasta 8.1.1.x • https://downloads.avaya.com/css/P8/documents/101075451 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •