CVE-2018-15615: CMS Supervisor Information Disclosure
Published Sep 24, 2018
·Updated
A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
Affected Software
3 affected components
Avaya Call Management System Supervisor=17.0.0
Avaya Call Management System Supervisor=18.0.1.0
Avaya Call Management System Supervisor=18.0.2.0
Event History
Sep 24, 2018
CVE Published
12:29 PM
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Avaya Call Management System vulnerability?
The vulnerability ID for this Avaya Call Management System vulnerability is CVE-2018-15615.
2
What is the severity of CVE-2018-15615?
The severity of CVE-2018-15615 is high (4.4).
3
Which component of Avaya Call Management System is affected by CVE-2018-15615?
The Supervisor component of Avaya Call Management System is affected by CVE-2018-15615.
4
Which versions of CMS Supervisor are affected by CVE-2018-15615?
Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
5
How can a local administrative user exploit CVE-2018-15615?
A local administrative user can exploit CVE-2018-15615 to extract sensitive information from users connecting to a remote CMS host.