First published: Thu Jun 24 2021(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services.
Credit: securityalerts@avaya.com securityalerts@avaya.com
Affected Software | Affected Version | How to fix |
---|---|---|
Avaya Aura Utility Services | >=7.0<=7.1.3 | |
>=7.0<=7.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Avaya Aura Utility Services vulnerability is CVE-2021-25650.
The severity of CVE-2021-25650 is high with a CVSS score of 8.8.
All 7.x versions of Avaya Aura Utility Services are affected by CVE-2021-25650.
CVE-2021-25650 can potentially allow a local user to execute specially crafted scripts as a privileged user, resulting in privilege escalation.
Please refer to the Avaya support website (https://support.avaya.com/css/P8/documents/101072728) for information on available fixes and patches for CVE-2021-25650.