Aura Communication Manager
Vendor:
First CVE: Nov 16, 2009 · Active for 16 years
10
Total CVEs
More Total CVEs than 89% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Aura Communication Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2009
16 years ago
Most Recent CVE
Oct 12, 2022
1,385 days ago
CVE Severity & Scoring
Aura Communication Manager10 CVEs
30%
70%
All CVEs353,240 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (60.0%)
Network4 (40.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low5 (50.0%)
High2 (20.0%)
None3 (30.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2943HIGH The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unli | Sep 30, 2010 | 8.1 | 45 | NO | YES |
CVE-2020-7029HIGH A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the System Management Interface Web component of Avaya Aura Communication Manager and Avaya Aura Messaging. This | Aug 11, 2020 | 8.8 | 27 | NO | NO |
CVE-2016-5285HIGH A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which c | Nov 15, 2019 | 7.5 | 24 | NO | NO |
CVE-2010-2492HIGH Buffer overflow in the ecryptfs_uid_hash macro in fs/ecryptfs/messaging.c in the eCryptfs subsystem in the Linux kernel before 2.6.35 might allow local users to gain privileges or | Sep 8, 2010 | 7.8 | 24 | NO | NO |
CVE-2022-2249MEDIUM Privilege escalation related vulnerabilities were discovered in Avaya Aura Communication Manager that may allow local administrative users to escalate their privileges. This issue | Oct 12, 2022 | 6.7 | 23 | NO | NO |
CVE-2018-15617HIGH A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affecte | Feb 1, 2019 | 7.5 | 23 | NO | NO |
CVE-2010-2798HIGH The gfs2_dirent_find_space function in fs/gfs2/dir.c in the Linux kernel before 2.6.35 uses an incorrect size value in calculations associated with sentinel directory entries, whic | Sep 8, 2010 | 7.8 | 23 | NO | NO |
CVE-2018-15611MEDIUM A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privil | Sep 27, 2018 | 6.7 | 21 | NO | NO |
CVE-2009-3939HIGH The poll_mode_io file for the megaraid_sas driver in the Linux kernel 2.6.31.6 and earlier has world-writable permissions, which allows local users to change the I/O mode of the dr | Nov 16, 2009 | 7.1 | 20 | NO | NO |
CVE-2010-2942MEDIUM The actions implementation in the network queueing functionality in the Linux kernel before 2.6.36-rc2 does not properly initialize certain structure members when performing dump o | Sep 21, 2010 | 5.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Aura Communication Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0 | 1 | 7.5 | 2.3% | 0 | 0 |
| 5.2 | 5 | 7.3 | 3.7% | 0 | 1 |
| 10.1.0.0 | 1 | 6.7 | 0.2% | 0 | 0 |