PT-2018-13117 · Avaya · Avaya Communication Manager
Lukasz Plonka
·
Published
2018-09-27
·
Updated
2019-10-09
·
CVE-2018-15611
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Avaya Aura Communication Manager versions 6.3.x through 7.1.3.0
Avaya Aura Communication Manager version 7.1.3.1 is not affected, so the range is prior to 7.1.3.1 for 7.x versions.
Description
A vulnerability in the local system administration component can allow an authenticated, privileged user on the local system to gain root privileges.
Recommendations
For Avaya Aura Communication Manager versions 6.3.x, update to version 7.1.3.1 or later.
For Avaya Aura Communication Manager versions 7.x prior to 7.1.3.1, update to version 7.1.3.1 or later.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avaya Communication Manager