CVE-2018-15611: Communication Manager Local Administrator PrivEsc
Published Sep 27, 2018
·Updated
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
Affected Software
2 affected components
Avaya Aura Communication Manager>=6.3.0.1<=6.3.17.0
Avaya Aura Communication Manager>=7.0<7.1.3.1
Event History
Sep 27, 2018
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2018-15611?
CVE-2018-15611 is a vulnerability in Avaya Aura Communication Manager that allows an authenticated user to gain root privileges.
2
What versions of Avaya Aura Communication Manager are affected?
Versions 6.3.x and all 7.x versions prior to 7.1.3.1 are affected.
3
How can an authenticated user exploit this vulnerability?
An authenticated user can exploit CVE-2018-15611 by leveraging their privileges on the local system to gain root privileges.
4
What is the severity of CVE-2018-15611?
The severity of CVE-2018-15611 is high with a CVSS score of 6.7.
5
How can I fix CVE-2018-15611?
To fix CVE-2018-15611, upgrade Avaya Aura Communication Manager to version 7.1.3.1 or later.