CVE-2021-25654: Avaya Aura Device Services Arbitrary Code Execution Vulnerability
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25654?
CVE-2021-25654 is an arbitrary code execution vulnerability in Avaya Aura Device Services that allows a local user to execute specially crafted scripts.
Which versions of Avaya Aura Device Services are affected by CVE-2021-25654?
CVE-2021-25654 affects versions 7.0 through 8.1.4.0 of Avaya Aura Device Services.
What is the severity of CVE-2021-25654?
CVE-2021-25654 has a severity score of 7.8, indicating a high severity.
How can I fix CVE-2021-25654?
To fix CVE-2021-25654, it is recommended to apply the necessary security patches or updates provided by Avaya.
Where can I find more information about CVE-2021-25654?
More information about CVE-2021-25654 can be found on Avaya's support website at https://support.avaya.com/css/P8/documents/101076523.