S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jun 12, 2025

CVE-2023-3722 Scanner

CVE-2023-3722 Scanner - OS Command Injection vulnerability in Avaya Aura Device Services

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-3722
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Aura Device Servicesby Avaya
AFFECTED< 8.1.4.1SAFE ✓≥ 8.1.4.1
aura_device_servicesby avaya
AFFECTED< 8.1.4.1SAFE ✓≥ 8.1.4.1
Updated Aug 22, 2026View on NVD →
Detail

Avaya Aura Device Services is a comprehensive suite of applications and features designed for enterprise communication networks. It is widely used in corporations to manage unified communications infrastructure, particularly those relying on Avaya systems. Avaya provides tools for device management, user authentication, and system monitoring to enhance network efficiency. Large enterprises and service providers use Avaya Aura to facilitate seamless business communications. In recent times, Avaya Aura Device Services has been essential for organizations looking to streamline their telecommunication requirements. By integrating these services, companies can ensure better connectivity and workflows across various departments.

The OS Command Injection vulnerability in Avaya Aura Device Services poses a significant risk to systems utilizing this application. It allows attackers to execute arbitrary commands on the host operating system via the web server running the application. This type of vulnerability arises when user input is improperly sanitized, enabling the execution of malicious commands. Remote Code Execution (RCE) is possible, making it a critical issue that must be addressed promptly. The vulnerability affects version 8.1.4.0 and earlier of the Avaya Aura Device Services. Exploiting this vulnerability could lead to unauthorized access and control over the server hosting the application.

The vulnerability in Avaya Aura Device Services is due to improper handling of input within the PhoneBackup endpoint. Attackers can upload a file with a .php extension and inject malicious PHP code. The server then executes this code when the file is accessed, allowing arbitrary commands to be run with the server's privileges. Specifically, the vulnerability leverages a PUT request to upload a PHP file and a subsequent GET request to execute the injected code. The vulnerable parameter is the file name and its content, which are processed without adequate validation. The risk is heightened by the lack of authentication during the file upload process.

Exploiting the OS Command Injection vulnerability can have dire consequences, including unauthorized system access, data breaches, and compromised server environments. Malicious actors could execute arbitrary commands, leading to information theft or complete system takeover. The affected systems might become part of a botnet, used for further attacks or illicit activities. Moreover, business operations dependent on the affected Avaya systems could be severely disrupted. Organizations could face financial losses, reputational damage, and potential legal ramifications due to data protection violations. It is crucial to address this vulnerability to prevent exploitation and ensure system security.

REFERENCES

Solution Advice
  • Apply the latest security patch provided by Avaya for Aura Device Services.
  • Implement input validation and sanitization filters for uploads to prevent command injection.
  • Restrict upload functionality to authenticated users only.
  • Monitor and log any attempts of file uploads containing scripts or unusual activity.
  • Conduct regular security audits and penetration tests to identify potential vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-3722 Scanner - OS Command Injection vulnerability in Avaya Aura Device Services S4E