๐Ÿ” CVE Alert

CVE-2022-2975

HIGH 7.7

Avaya Aura Application Enablement Services weak permissions in web application

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.

CWE CWE-269
Vendor avaya
Product avaya aura application enablement services
Published Oct 6, 2022
Last Updated Aug 3, 2024
Stay Ahead of the Next One

Get instant alerts for avaya avaya aura application enablement services

Be the first to know when new high vulnerabilities affecting avaya avaya aura application enablement services are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Avaya / Avaya Aura Application Enablement Services
10.1.x โ‰ค 10.1.0.1 8.x โ‰ค 8.1.3.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
download.avaya.com: https://download.avaya.com/css/public/documents/101083688