CVE-2018-15615: Avaya Call Management System Supervisor

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the Supervisor component of Avaya Call Management System allows local administrative user to extract sensitive information from users connecting to a remote CMS host. Affected versions of CMS Supervisor include R17.0.x and R18.0.x.

Affected products

  • Avaya Call Management System Supervisor: version 17.0.0 only; version 18.0.1.0 only; version 18.0.2.0 only

Published 2018-09-24. Last modified 2026-06-17.