San Antonio, TX – Digital Defense, Inc., a leading provider of Vulnerability Management as a Service™ (VMaaS), today announced that its Vulnerability Research Team (VRT) uncovered a previously undisclosed vulnerability within the Avaya Application Enablement Services (AES) Management Console. The vulnerability would allow remote code execution if a specially crafted message was sent to the AES server. Digital Defense and Avaya rate this vulnerability as having a high security impact to the system.
“Avaya has been very responsive and prompt to verify the flaw and has released a patch to resolve the issue,” said Larry Hurtado, CEO of Digital Defense, Inc. “Our team has once again sounded the alarm to prevent a major cyber incident from occurring.”
What You Can Do
The patch Avaya issued to resolve the condition is available in the Avaya Security Advisory ASA-2017-088. Digital Defense’s Frontline Vulnerability Manager™ includes a check for the flaw.
Digital Defense Research Methodology and Practices
The Digital Defense VRT regularly works with organizations in the responsible disclosure of zero-day vulnerabilities. The expertise of the VRT, when coupled with the company’s next generation hybrid cloud platform, Frontline Vulnerability Manager, enables early detection capabilities. When zero-days are discovered and internally validated, the VRT immediately contacts the affected vendor to notify the organization of the new finding(s) and then assists, wherever possible, with the vendor’s remediation actions.