Vulnerabilities > CVE-2018-15616 - Deserialization of Untrusted Data vulnerability in Avaya Aura System Platform

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
avaya
CWE-502

Summary

A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.

Vulnerable Configurations

Part Description Count
Hardware
Avaya
1

Common Weakness Enumeration (CWE)