7.8
CVE-2021-25654
- EPSS 0.21%
- Veröffentlicht 25.06.2021 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:55:13
- Quelle securityalerts@avaya.com
- CVE-Watchlists
- Unerledigt
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Avaya ≫ Aura Device Services Version >= 7.0 <= 8.1.4.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.439 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| securityalerts@avaya.com | 6.2 | 0.7 | 5.5 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L
|
CWE-378 Creation of Temporary File With Insecure Permissions
Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.