A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.
2018-09-24T12:29:00.237
2024-11-21T03:51:10.867
Modified
CVSSv3.0: 7.2 (HIGH)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | avaya | call_management_system_supervisor | 17.0.0 | Yes |
| Application | avaya | call_management_system_supervisor | 18.0.1.0 | Yes |
| Application | avaya | call_management_system_supervisor | 18.0.2.0 | Yes |