Lucene search

K
nvd[email protected]NVD:CVE-2021-25657
HistorySep 02, 2022 - 1:15 a.m.

CVE-2021-25657

2022-09-0201:15:07
CWE-269
web.nvd.nist.gov
4
vulnerability
avaya
ip office
escalation
privileges
admin lite
usb creator
local user

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

Affected configurations

Nvd
Node
avayaip_officeRange<11.1
OR
avayaip_officeMatch11.1-
OR
avayaip_officeMatch11.1feature_pack1
OR
avayaip_officeMatch11.1feature_pack1_service_pack1
OR
avayaip_officeMatch11.1feature_pack2
OR
avayaip_officeMatch11.1feature_pack2_service_pack1
VendorProductVersionCPE
avayaip_office*cpe:2.3:a:avaya:ip_office:*:*:*:*:*:*:*:*
avayaip_office11.1cpe:2.3:a:avaya:ip_office:11.1:-:*:*:*:*:*:*
avayaip_office11.1cpe:2.3:a:avaya:ip_office:11.1:feature_pack1:*:*:*:*:*:*
avayaip_office11.1cpe:2.3:a:avaya:ip_office:11.1:feature_pack1_service_pack1:*:*:*:*:*:*
avayaip_office11.1cpe:2.3:a:avaya:ip_office:11.1:feature_pack2:*:*:*:*:*:*
avayaip_office11.1cpe:2.3:a:avaya:ip_office:11.1:feature_pack2_service_pack1:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

5.1%

Related for NVD:CVE-2021-25657