CVE-2018-15617: Communication Manager Denial of Service
Published Feb 1, 2019
·Updated
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
Affected Software
3 affected components
Avaya Aura Communication Manager>=6.3.0.1<=6.3.17.0
Avaya Aura Communication Manager>=7.0<7.1.3.2
Avaya Aura Communication Manager>=8.0<8.0.1
Event History
Feb 1, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-15617.
2
What component of Avaya Aura Communication Manager is affected by this vulnerability?
The capro (Call Processor) process component of Avaya Aura Communication Manager is affected.
3
What is the severity rating of CVE-2018-15617?
The severity rating of CVE-2018-15617 is high with a value of 7.5.
4
How can a remote, unauthenticated user exploit this vulnerability?
A remote, unauthenticated user can exploit this vulnerability to cause denial of service.
5
Which versions of Avaya Aura Communication Manager are affected by this vulnerability?
The affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.