Description
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
CVSS Metrics
- Vector
- CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
- Attack Vector
- local
- Complexity
- high
- Privileges
- high
- User Action
- required
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- high
- Availability
- high
- Weaknesses
- CWE-284NVD-CWE-noinfo
Metadata
- Primary Vendor
- AVAYA
- Published
- 9/27/2018
- Last Modified
- 11/21/2024
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
avaya : aura_communication_manageravaya : aura_communication_manager
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.