CVE-2022-2975
Avaya Aura Application Enablement Services weak permissions in web application
CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability related to weak permissions was detected in Avaya Aura Application Enablement Services web application, allowing an administrative user to modify accounts leading to execution of arbitrary code as the root user. This issue affects Application Enablement Services versions 8.0.0.0 through 8.1.3.4 and 10.1.0.0 through 10.1.0.1. Versions prior to 8.0.0.0 are end of manufacturing support and were not evaluated.
| CWE | CWE-269 |
| Vendor | avaya |
| Product | avaya aura application enablement services |
| Published | Oct 6, 2022 |
| Last Updated | Aug 3, 2024 |
Stay Ahead of the Next One
Get instant alerts for avaya avaya aura application enablement services
Be the first to know when new high vulnerabilities affecting avaya avaya aura application enablement services are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Avaya / Avaya Aura Application Enablement Services
10.1.x โค 10.1.0.1 8.x โค 8.1.3.4