Skip to content
Noroxi

Polycom records

39 published records for vendor polycom.

All records

39 records
  • Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    polycom · realpresence resource managerSep 19, 2017

  • An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.

    CriticalCVSS 9.8No exploitEPSS 5%

    polycom · group seriesMay 13, 2019

  • Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthor

    CriticalCVSS 10.0No exploitEPSS 2%

    polycom · viewstation 128Jan 7, 2003

  • An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Devel

    CriticalCVSS 9.8No exploitEPSS 3%

    polycom · hdx system softwareFeb 10, 2020

  • CVE-2012-6610
    38Monitor

    Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demon

    HighCVSS 8.8WeaponizedEPSS 11%

    polycom · hdx video end pointsJan 28, 2020

  • Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password res

    HighCVSS 8.8No exploitEPSS 2%

    polycom · vvx 400 firmwareOct 4, 2021

  • Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 ar

    HighCVSS 8.8No exploitEPSS 2%

    polycom · unified communications softwareAug 25, 2017

  • CVE-2018-7565
    35Monitor

    CSRF exists on Polycom QDX 6000 devices.

    HighCVSS 8.8No exploitEPSS 0%

    polycom · qdx 6000 firmwareMar 7, 2018

  • A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC S

    HighCVSS 8.3No exploitEPSS 2%

    polycom · unified communications softwareJul 29, 2019

  • On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP add

    HighCVSS 8.0No exploitEPSS 3%

    polycom · obihai obi1022 firmwareAug 1, 2019

  • CVE-2007-3369
    32Monitor

    Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a

    HighCVSS 7.8No exploitEPSS 2%

    polycom · soundpoint ip 601Jun 22, 2007

  • CVE-2007-3368
    32Monitor

    Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial

    HighCVSS 7.8No exploitEPSS 2%

    polycom · soundpoint ip 650Jun 22, 2007

  • CVE-2006-5233
    32Monitor

    Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via

    HighCVSS 7.8No exploitEPSS 2%

    polycom · soundpoint ip 301Oct 10, 2006

  • CVE-2015-4681
    32Monitor

    Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwo

    HighCVSS 7.8Proof of conceptEPSS 2%

    polycom · realpresence resource managerSep 19, 2017

  • CVE-2002-0628
    31Monitor

    The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rem

    HighCVSS 7.5No exploitEPSS 2%

    polycom · viewstation 128Jan 7, 2003

  • CVE-2012-6609
    31Monitor

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attac

    HighCVSS 7.5No exploitEPSS 2%

    polycom · hdx video end pointsJan 28, 2020

  • CVE-2015-8300
    31Monitor

    Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\p

    HighCVSS 7.8No exploitEPSS 1%

    polycom · btoe connectorAug 28, 2017

  • CVE-2002-0627
    30Monitor

    The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requ

    HighCVSS 7.5No exploitEPSS 2%

    polycom · viewstation 128Jan 7, 2003

  • Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explic

    HighCVSS 7.5No exploitEPSS 1%

    polycom · realpresence web suiteJun 20, 2018

  • CVE-2015-4682
    28Monitor

    Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP PO

    MediumCVSS 6.5Proof of conceptEPSS 5%

    polycom · realpresence resource managerSep 19, 2017

  • CVE-2015-4685
    28Monitor

    Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scri

    HighCVSS 7.0Proof of conceptEPSS 1%

    polycom · realpresence resource managerSep 19, 2017

  • An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.

    HighCVSS 7.2No exploitEPSS 1%

    polycom · hdx system softwareMar 12, 2020

  • CVE-2015-4684
    27Monitor

    Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated u

    MediumCVSS 6.5Proof of conceptEPSS 5%

    polycom · realpresence resource managerSep 19, 2017

  • An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the ad

    MediumCVSS 6.8No exploitEPSS 0%

    polycom · realpresence debut firmwareJun 13, 2019

  • VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,

    MediumCVSS 6.8No exploitEPSS 0%

    polycom · unified communications softwareApr 23, 2019