Vulnerability Description
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Avaya | Aura Communication Manager | >= 6.3.0.1, <= 6.3.17.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106826Third Party AdvisoryVDB Entry
- https://downloads.avaya.com/css/P8/documents/101055396Vendor Advisory
- http://www.securityfocus.com/bid/106826Third Party AdvisoryVDB Entry
- https://downloads.avaya.com/css/P8/documents/101055396Vendor Advisory
FAQ
What is CVE-2018-15617?
CVE-2018-15617 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6...
How severe is CVE-2018-15617?
CVE-2018-15617 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-15617?
Check the references section above for vendor advisories and patch information. Affected products include: Avaya Aura Communication Manager.