CVE-2022-2249
HIGHAvaya Aura Communication Manager - Improper Privilege Management
Title source: ruleDescription
Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue affects Communication Manager versions 8.0.0.0 through 8.1.3.3 and 10.1.0.0.
Scores
CVSS v3
7.7
EPSS
0.0006
EPSS Percentile
17.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
Classification
CWE
CWE-269
Status
published
Affected Products (2)
avaya/aura_communication_manager
< 8.1.3.4
avaya/aura_communication_manager
Timeline
Published
Oct 12, 2022
Tracked Since
Feb 18, 2026