CVE-2023-3527: Avaya Call Management System
Medium severity, CVSS 6.8. EPSS: 0.6% chance of exploitation in the next 30 days.
A CSV injection vulnerability was found in the Avaya Call Management System (CMS) Supervisor web application which allows a user with administrative privileges to input crafted data which, when exported to a CSV file, may attempt arbitrary command execution on the system used to open the file by a spreadsheet software such as Microsoft Excel.
Affected products
- Avaya Call Management System: before 20.0.0.0 (fixed in 20.0.0.0)
Published 2023-07-18. Last modified 2026-06-17.