# CVE-2024-4196

## Summary

- **CVE ID:** CVE-2024-4196
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-782
- **Published:** Jun 25, 2024
- **Last Modified:** Mar 13, 2026

## Description

An improper input validation vulnerability  was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.

## Affected Products

- Avaya — IP Office (0)

## References

- [CNA](https://download.avaya.com/css/public/documents/101090768)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.59%
- **EPSS Percentile:** 46.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._