← Vulnerability feed

Vulnerability record · CVE-2021-25657 · published 2 September 2022

CVE-2021-25657: Avaya ip office improper privilege management vulnerability

Avaya · Ip Office

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

7.8 CVSS 3.1 High EPSS 0.26% · top 84.4% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.26%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A privilege escalation vulnerability was discovered in Avaya IP Office Admin Lite and USB Creator that may potentially allow a local user to escalate privileges. This issue affects Admin Lite and USB Creator 11.1 Feature Pack 2 Service Pack 1 and earlier versions.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-25657 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-4197Avaya ip office unrestricted file upload vulnerabilityAn unrestricted file upload vulnerability in Avaya IP Office was discovered that could allow remote command or code execution via the One-X component…EPSS 0.78%9.8CVE-2024-4196Avaya ip office vulnerabilityAn improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafte…EPSS 0.59%9.6CVE-2017-11309Avaya ip office memory buffer overflow vulnerabilityBuffer overflow in the SoftConsole client in Avaya IP Office before 10.1.1 allows remote servers to execute arbitrary code via a long response.EPSS 9.4%8.8CVE-2018-15610Avaya ip office improper access control vulnerabilityA vulnerability in the one-X Portal component of Avaya IP Office allows an authenticated attacker to read and delete arbitrary files on the system. A…EPSS 1.8%7.5CVE-2019-7005Avaya ip office information exposure vulnerabilityA vulnerability was discovered in the web interface component of IP Office that may potentially allow a remote, unauthenticated user with network acc…EPSS 1.2%7.5CVE-2016-5285Mozilla nss null pointer dereference vulnerabilityA Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_Comput…EPSS 2.3%5.5CVE-2020-7030Avaya ip office insufficiently protected credentials vulnerabilityA sensitive information disclosure vulnerability was discovered in the web interface component of IP Office that may potentially allow a local user t…EPSS 1.0%5.4CVE-2018-15614Avaya ip office cross-site scripting vulnerabilityA vulnerability in the one-x Portal component of IP Office could allow an authenticated user to perform stored cross site scripting attacks via field…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2021-25657), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.