CyberPoint NORDIC researchers discover a high-severity vulnerability (CVE-2022-2975) affecting Avaya telecommunication and VoIP products

Posted: 10.7.22

CyberPoint NORDIC lead Alex Levesque discovered a vulnerability in Avaya Aura Application Enablement Services servers. Following CyberPoint's responsible disclosure policy, we provided a writeup of the discovery to Avaya's Product Security Team, who released an Avaya Security Advisory, assigned CVE-2022-2975, and published a patch to the software. The vulnerability allows for privilege escalation and execution of arbitrary code as the root user. CyberPoint will release a full writeup of the discovery 30 days after patch release. To anyone with Avaya systems, please update at your earliest convenience!

More about this CVE can be found at the following URLs:

https://download.avaya.com/css/public/documents/101083688
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-2975

CyberPoint NORDIC researchers discover a high-severity vulnerability (CVE-2022-2975) affecting Avaya telecommunication and VoIP products

The mission of CyberPoint's NORDIC Team is to relentlessly pursue novel technologies and techniques to support customer operations, discovering the vulnerabilities before the adversary does in order to Protect What's Invaluable to you. We are an applied research center, where the research is driven by requirements with an eye to develop new capabilities.

Contact NORDIC

NORDIC engineers work to your requirements: rapid research & development in a commercial facility, and supporting government customers with heightened security requirements are both within our expertise.

Contact us with queries about how we can support your mission today.

 

 

Recent Posts

Traditional Perimeter Security and Zero Trust – Are they Really That Different?

Evaluating Vendors for Zero Trust System Integration

Getting to Ground Zero (Trust)

HTTP/2 and You: When hypertext gets too/2hyper

Graphing the Future: Harnessing the Power of Graph Neural Networks for Cybersecurity

CyberPoint's Vlad Gostomelsky Appears on Paul's Security Weekly Podcast

Blackbeard's Ransom: Ransomware of Source Code is a Real Threat

OpenSSL 3.0 CVE-2022-3786 Buffer Overflow Vulnerability

CyberPoint NORDIC researchers discover a high-severity vulnerability (CVE-2022-2975) affecting Avaya telecommunication and VoIP products

Old Exploits Up to Old and New Tricks: TrickBot

Major Leak from Conti Ransomware Group Translated

Apache Log4j Vulnerabilities: The Basics

Sylphs in the Cloud

Got MODBUS? Please Check!

Protecting Legacy Encryption from Quantum Computing: A Possible Solution.

An alternative approach to quantifying cyber risk using comprehensive attack surface evaluation assessments and Value-at-Risk modeling.

Worst-Case Complexity of Ford-Fulkerson

Cyberspace — the Next Utility Infrastructure

Accelerating Capabilities Acquisition Through OTAs and PIAs: A Contractor Perspective

Malicious Browser Extensions

Using Compression to Compare Objects

Learning in the Dark: Lessons Learned in Unsupervised Learning

Logging Keystrokes with Event Tracing for Windows (ETW)

The Human Interface Device (HID) Attack, aka USB Drive-By

Software Defined Security at CyberPoint

The Minimum

Share

If you like CyberPoint and think others would too, we'd appreciate it if you would spread the word!