LiveActive security incident?Get immediate response
CVE Record

CVE-2018-15611: Communication Manager Local Administrator PrivEsc

A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.

MediumCVSS 6.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2018-15611 is a local privilege escalation in Avaya Aura Communication Manager. A user who already has privileged local system access may be able to gain root privileges, turning a limited administrative foothold into full system control.

Executive priority

Treat this as a targeted infrastructure hardening issue, not an internet-scale emergency. Prioritize remediation where Avaya Communication Manager supports critical voice operations or where many administrators, vendors, or service accounts have local access.

Technical view

The issue affects the local system administration component of Avaya Aura Communication Manager 6.3.x and 7.x before 7.1.3.1. It is mapped to CWE-284, with CVSS 6.3: local attack vector, high complexity, high privileges required, user interaction required, and high confidentiality, integrity, and availability impact.

Likely exposure

Exposure is limited to organizations running affected Avaya Aura Communication Manager versions where privileged local system access is possible. This is most relevant to voice infrastructure administrators, managed service access, jump hosts, and compromised privileged accounts.

Exploitation context

The source bundle does not show CISA KEV listing or cited evidence of active exploitation. The vulnerability requires authenticated privileged local access and user interaction, so it is not described as remotely exploitable from the public internet.

Researcher notes

Evidence is limited to the CVE record and Avaya reference in the bundle. Do not assume remote exploitability, public exploit availability, or broader Avaya product impact. The key validation question is whether affected local administration components remain deployed on vulnerable versions.

Mitigation direction

  • Review the Avaya advisory for supported remediation guidance.
  • Upgrade affected 7.x deployments to 7.1.3.1 or later where applicable.
  • For 6.3.x systems, confirm vendor-supported upgrade or mitigation options.
  • Restrict local administrative access to trusted, monitored users only.
  • Audit privileged access paths to Communication Manager hosts.

Validation and detection

  • Inventory all Avaya Aura Communication Manager deployments and versions.
  • Identify systems running 6.3.x or 7.x before 7.1.3.1.
  • Review local administrator accounts and recent privileged sessions.
  • Confirm whether Avaya remediation has been applied.
  • Check logs for unexpected privilege changes or root-level activity.
Prepared
Confidence
high
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · medium confidence lookup

CWE-284: Authorization and privilege behavior lookup

Authorization weaknesses can support privilege escalation and valid-account review, depending on exploit path. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2018-15611 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
6.3 (3.0)
Known Exploited
No
Published

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
6.3CVSS 3.0MediumCVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H0.35.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.0 score

6.3Medium
CVSS 3.0 vector shape for CVE-2018-15611Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AvayaCommunication Manager7.1.3.1, 6.3.xListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-284 · source CWE mapping

Improper Access Control

Improper Access Control represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.