CVE-2017-12857CVE-2017-12857

Affected configuration(s):

cpe:/o:polycom:unified_communications_software:4.0.11
cpe:/o:polycom:unified_communications_software:5.4.4
cpe:/o:polycom:unified_communications_software:5.4.6
cpe:/o:polycom:unified_communications_software:5.5.1

Date published: 2017-08-25T15:29:00.270-04:00

Date last modified: 2017-09-12T21:29:08.583-04:00

CVSS Score: 4.0

Principal attack vector: NETWORK

Complexity:  LOW

Reference URL: http://support.polycom.com/content/dam/polycom-support/global/documentation/security-advisory-information-disclosure-on-polycom-voice-products-v1.0.pdf

Summary: Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone’s memory which could contain an administrator’s password or other sensitive information.

CategoriesUncategorised

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.