PT-2021-3463 · Avaya · Avaya Aura Device Services

Gerardo Iglesias

+1

·

Published

2021-06-25

·

Updated

2022-08-01

·

CVE-2021-25654

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Avaya Aura Device Services versions 7.0 through 8.1.4.0
Description An arbitrary code execution issue was discovered in Avaya Aura Device Services, potentially allowing a local user to execute specially crafted scripts. The vulnerability is related to the creation of temporary files with insecure permissions.
Recommendations For versions 7.0 through 8.1.4.0, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2021-03327
CVE-2021-25654

Affected Products

Avaya Aura Device Services