CVE-2021-25652: Avaya Aura Appliance Virtualization Platform Utilities Sensitive Information Disclosure Vulnerability
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this information disclosure vulnerability?
The vulnerability ID for this information disclosure vulnerability is CVE-2021-25652.
What is the affected software?
The affected software is Avaya Aura Appliance Virtualization Platform version 8.0.0.0 to 8.1.3.1.
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 5.5.
What is the impact of this vulnerability?
This vulnerability may potentially allow any local user to access system functionality and configuration information.
Is there a fix available for this vulnerability?
Yes, Avaya has released a security advisory which provides guidance on how to address this vulnerability.