• SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us

Call us today! 844-OCD-TECH

Find our Location
OCD TechOCD Tech
  • SecurePath for Auto Dealers
  • Services
    • SOC Reporting Services
      • SOC 2® Readiness Assessment
      • SOC 2® Reports
      • SOC 3® Reports
      • SOC for Cybersecurity® Reports
    • IT Advisory Services
      • IT Vulnerability Assessment
      • Network Penetration Testing
      • Privileged Access Management
      • Social Engineering Testing
      • Virtual CISO (vCISO)
      • Written Information Security Program (“WISP”)
      • IT General Controls Audit & Compliance
    • IT Government Compliance
      • CMMC Cybersecurity Services & Compliance
      • DFARS Compliance
      • FTC Safeguards Compliance
  • Industries
    • Financial Services
    • Government
    • Auto Dealerships
    • Enterprise
  • Blog
  • About Us
    • Meet The Team
    • Jobs
  • Contact Us
XSS Image
https://www.flickr.com/photos/christiaancolen/26327769401

CVE-2019-7004

December 12, 2019 Posted by Scott Goodwin IT Security

On an external penetration test earlier this year, OCD Tech came across an instance of Avaya’s IP Office Web Collaboration software on a client’s in-scope internet-facing system. This web-based software allows employees and external users to host and join meetings leveraging Avaya’s business Voice-over-IP (VoIP) software solutions. While use of the platform requires credentials, a login page was exposed to the internet to allow external users a means to join meetings. Via a dedicated review of this software, which was fully patched at the time of the test, the OCD Tech penetration testing team was able to identify a new cross site scripting vulnerability affecting the “Username” parameter of the login form. By injecting a specialized string into the username field, the OCD Tech team was able to execute arbitrary JavaScript in the context of the web browser. OCD Tech worked with the vendor to responsibly disclose the identified vulnerability, which was acknowledged and patched by Avaya within a reasonable timeframe. After the patch was made available to Avaya’s customers, a public disclosure of the vulnerability was released, and OCD Tech was awarded CVE-2019-7004 for the discovery of this cross site scripting vulnerability. OCD Tech prides itself on professional penetration testing services, and responsible disclosure of newly identified vulnerabilities. For more information, please see the following vulnerability disclosures:

The National Institute for Standards and Technology National Vulnerability Database

Mitre Common Vulnerabilities and Exposures Database:

Avaya Security Advisory (ASA-2019-213)

Congratulations to Daniel Bohan, OSCP of OCD Tech, for their discovery of this net-new vulnerability, and taking responsible steps to help Avaya secure their customer’s systems.

Share
0
Scott Goodwin

About Scott Goodwin

Scott manages the Information Security Advisory Services practice within OCD Tech. Prior to joining the firm, he graduated from the University of Massachusetts Boston with a degree in Physics. Scott’s primary engagements include security advisory services, and security assessments against industry standard frameworks including NIST 800-53 and the NIST Cybersecurity Framework, as well as NIST 800-171 assessments for multiple clients in the defense and aerospace sector. Currently, Scott oversees many technical engagements, including vulnerability assessments, and is a lead penetration tester for OCD Tech.  Scott is directly responsible for the identification of three (3) previously unknown vendor software vulnerabilities which have been registered with Mitre’s Common Vulnerabilities and Exposures (CVE) database as CVE-2018-11628, 2019-7004, and 2019-19774.  Scott is also the key developer on the OCD Tech open source discovery platform, Scrapy. The platform identifies public domain information and provides reporting and alerting for OCD Tech clients upon discovery of key sensitive company/personal information.

You also might be interested in

OCD Tech, the IT Audit & Security division of O’Connor & Drew, P.C., Awarded Information Technology Contract for the Commonwealth of Massachusetts, PRF78

Dec 21, 2020

OCD Tech has recently been awarded the Massachusetts statewide contract for Audit: Specialty: Information Technology

FTC-Safeguards-Rule-rundown

Are you prepared for the FTC Safeguards Rule Requirements?

Feb 9, 2022

The Federal Trade Commission (FTC) recently released their Final Rule to amend the Standards for Safeguarding Customer Information.

Wireless-Vulnerability

Wireless Data Exfiltration Vulnerability

May 13, 2021

On May 12, 2021, a newer vulnerability affecting most wireless-enabled devices was discovered and an advisory was issued by CIS (Center for Internet Security). The CVEs are listed below:

Find us on

Contact Us

We're not around right now. But you can send us an email and we'll get back to you, asap.

Send Message
OCD Tech logo Audit. Security. Assurance.

IT Audit | Cybersecurity | IT Assurance | IT Security Consultants – OCD Tech is a technology consulting firm serving the IT security and consulting needs of businesses in Boston (MA), Braintree (MA) and across New England. We primarily serve Fortune 500 companies including auto dealers, financial institutions, higher education, government contractors, and not-for-profit organizations with SOC 2 reporting, CMMC readiness, IT Security Audits, Penetration Testing and Vulnerability Assessments. We also provide dark web monitoring, DFARS compliance, and IT general controls review.

Contact Info

  • OCD Tech
  • 25 BHOP, Suite 407, Braintree MA, 02184
  • 844-623-8324
  • https://ocd-tech.com

Follow Us

Videos

Check Out the Latest Videos From OCD Tech!

Services

SOC Reporting Services
– SOC 2 ® Readiness Assessment
– SOC 2 ®
– SOC 3 ®
– SOC for Cybersecurity ®

IT Advisory Services
– IT Vulnerability Assessment
– Penetration Testing
– Privileged Access Management
– Social Engineering
– WISP
– General IT Controls Review

IT Government Compliance Services
– CMMC
– DFARS Compliance
– FTC Safeguards vCISO

Industries

  • Financial Services
  • Government
  • Enterprise
  • Auto Dealerships

© 2025 — OCD Tech: IT Audit - Cybersecurity - IT Assurance

  • OCD Tech
  • About Us
  • Contact Us
Prev Next