ZeroHour

CVE-2018-6635

CVSS 3.0
7.5 high
EPSS
1%p66
Published
()
Modified
Description

System Manager in Avaya Aura before 7.1.2 does not properly use SSL in conjunction with authentication, which allows remote attackers to bypass intended Remote Method Invocation (RMI) restrictions, aka SMGR-26896.

Vendors
avaya
Products
aura
Weakness
CWE-326
Vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.