Back to Database
Status published
High
CVE-2021-25650
Avaya Aura Utility Services Privilege Escalation Vulnerability
Vulnerability Description
A privilege escalation vulnerability was discovered in Avaya Aura Utility Services that may potentially allow a local user to execute specially crafted scripts as a privileged user. Affects all 7.x versions of Avaya Aura Utility Services
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-25650
Credits & Attribution
No credits recorded in the NVD database.
More from Avaya
View All →CVE-2025-1041
Avaya Call Management System RCE vulnerability
Critical
9.9
CVE-2024-7480
Improper access control in Avaya Aura System Manager
Medium
4.2
CVE-2024-7477
Avaya Aura System Manager SQL injection vulnerability
Medium
6.5
CVE-2024-4197
Avaya IP Office One-X Portal File Upload Vulnerability
Critical
9.9
CVE-2024-4196
Avaya IP Office Web Control RCE Vulnerability
Critical
10
Affected Vendor
Avaya
View all reports →Affected Software
Avaya Aura Utility Services
Vulnerable Versions:
7.0.0.0
Timeline
Official Publish:
June 24th, 2021
Last Modified:
August 3rd, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N