Vulnerability Details CVE-2021-25652
An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Appliance Virtualization Platform Utilities (AVPU). This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects versions 8.0.0.0 through 8.1.3.1 of AVPU.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 36.5%
CVSS Severity
CVSS v3 Score 4.9
CVSS v2 Score 2.1
Products affected by CVE-2021-25652
-
cpe:2.3:a:avaya:aura_appliance_virtualization_platform:8.0.0.0
-
cpe:2.3:a:avaya:aura_appliance_virtualization_platform:8.1.3.1