SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-25649

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services.

MEDIUM 5.5EPSS 0.62%

Does this matter?

Lower severity and a low EPSS score (0.62%). Track it; it rarely justifies an emergency change on its own.

Description

An information disclosure vulnerability was discovered in the directory and file management of Avaya Aura Utility Services. This vulnerability may potentially allow any local user to access system functionality and configuration information that should only be available to a privileged user. Affects all 7.x versions of Avaya Aura Utility Services

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.62% probability · 48th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
avaya/aura utility services
Source
securityalerts@avaya.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.