Poly records
13 published records for vendor poly.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-404 Improper Resource Shutdown or Release1
- CWE-620 Unverified Password Change1
- CWE-693 Protection Mechanism Failure1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-26479No exploit | An issue was discovered in Poly EagleEye Director II before 2.2.2.1.poly · eagleeye director ii firmware · CWE-863 | Critical9.8 | — | 2.1% | Jul 17, 2022 |
36Monitor | CVE-2018-17875No exploit | A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commandspoly · trio 8800 firmware | High8.8 | — | 2.7% | Dec 28, 2021 |
35Monitor | CVE-2022-26482No exploit | An issue was discovered in Poly EagleEye Director II before 2.2.2.1.poly · eagleeye director ii firmware · CWE-78 | High7.2 | — | 22.8% | Jul 17, 2022 |
35Monitor | CVE-2022-26481No exploit | An issue was discovered in Poly Studio before 3.7.0.poly · studio x30 firmware · CWE-78 | High8.8 | — | 1.5% | Jul 17, 2022 |
30Monitor | CVE-2023-4463No exploit | Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of servicepoly · ccx 400 firmware · CWE-404 | High7.5 | — | 1.0% | Dec 29, 2023 |
30Monitor | CVE-2023-4468No exploit | Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorizationpoly · trio 8800 firmware · CWE-862 | High7.6 | — | 0.3% | Dec 29, 2023 |
29Monitor | CVE-2023-4464No exploit | Poly VVX 601 Diagnostic Telnet Mode os command injectionpoly · ccx 400 firmware · CWE-78 | High7.2 | — | 3.3% | Dec 29, 2023 |
29Monitor | CVE-2021-37145No exploit | A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attackerpoly · cx5500 firmware · CWE-77 | High7.2 | — | 2.0% | Sep 7, 2021 |
26Monitor | CVE-2023-4465No exploit | Poly VVX 601 Configuration File Import unverified password changepoly · ccx 400 firmware · CWE-620 | Medium6.5 | — | 0.5% | Dec 29, 2023 |
26Monitor | CVE-2023-4467No exploit | Poly Trio 8800 Test Automation Mode backdoorpoly · trio 8800 firmware · CWE-912 | Medium6.6 | — | 0.3% | Dec 29, 2023 |
23Monitor | CVE-2023-4462No exploit | Poly VVX 601 Web Configuration Application random valuespoly · ccx 400 firmware · CWE-330 | Medium5.9 | — | 0.9% | Dec 29, 2023 |
21Monitor | CVE-2023-24282No exploit | An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.poly · trio 8800 firmware · CWE-79 | Medium5.4 | — | 0.5% | Mar 8, 2023 |
19Monitor | CVE-2023-4466No exploit | Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanismpoly · ccx 400 firmware · CWE-693 | Medium4.9 | — | 0.5% | Dec 29, 2023 |
- CVE-2022-2647940Plan
An issue was discovered in Poly EagleEye Director II before 2.2.2.1.
CriticalCVSS 9.8No exploitEPSS 2%poly · eagleeye director ii firmwareJul 17, 2022
- CVE-2018-1787536Monitor
A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands
HighCVSS 8.8No exploitEPSS 3%poly · trio 8800 firmwareDec 28, 2021
- CVE-2022-2648235Monitor
An issue was discovered in Poly EagleEye Director II before 2.2.2.1.
HighCVSS 7.2No exploitEPSS 23%poly · eagleeye director ii firmwareJul 17, 2022
- CVE-2022-2648135Monitor
An issue was discovered in Poly Studio before 3.7.0.
HighCVSS 8.8No exploitEPSS 2%poly · studio x30 firmwareJul 17, 2022
- CVE-2023-446330Monitor
Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of service
HighCVSS 7.5No exploitEPSS 1%poly · ccx 400 firmwareDec 29, 2023
- CVE-2023-446830Monitor
Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization
HighCVSS 7.6No exploitEPSS 0%poly · trio 8800 firmwareDec 29, 2023
- CVE-2023-446429Monitor
Poly VVX 601 Diagnostic Telnet Mode os command injection
HighCVSS 7.2No exploitEPSS 3%poly · ccx 400 firmwareDec 29, 2023
- CVE-2021-3714529Monitor
A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker
HighCVSS 7.2No exploitEPSS 2%poly · cx5500 firmwareSep 7, 2021
- CVE-2023-446526Monitor
Poly VVX 601 Configuration File Import unverified password change
MediumCVSS 6.5No exploitEPSS 0%poly · ccx 400 firmwareDec 29, 2023
- CVE-2023-446726Monitor
Poly Trio 8800 Test Automation Mode backdoor
MediumCVSS 6.6No exploitEPSS 0%poly · trio 8800 firmwareDec 29, 2023
- CVE-2023-446223Monitor
Poly VVX 601 Web Configuration Application random values
MediumCVSS 5.9No exploitEPSS 1%poly · ccx 400 firmwareDec 29, 2023
- CVE-2023-2428221Monitor
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
MediumCVSS 5.4No exploitEPSS 0%poly · trio 8800 firmwareMar 8, 2023
- CVE-2023-446619Monitor
Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanism
MediumCVSS 4.9No exploitEPSS 1%poly · ccx 400 firmwareDec 29, 2023