CVE-2023-3722: Avaya Aura Device Services

Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.

An OS command injection vulnerability was found in the Avaya Aura Device Services Web application which could allow remote code execution as the Web server user via a malicious uploaded file. This issue affects Avaya Aura Device Services version 8.1.4.0 and earlier.

Affected products

  • Avaya Aura Device Services: up to and including 8.1.4.0

Published 2023-07-19. Last modified 2026-06-17.