Polycom records
39 published records for vendor polycom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.6%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls2
The weakness classes this vendor ships most often: where to look.
CWEAll records
39 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2015-4683Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privilegespolycom · realpresence resource manager · CWE-264 | Critical9.8 | — | 6.9% | Sep 19, 2017 |
41Plan | CVE-2018-15128No exploit | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.polycom · group series · CWE-119 | Critical9.8 | — | 5.2% | May 13, 2019 |
41Plan | CVE-2002-0626No exploit | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorpolycom · viewstation 128 | Critical10.0 | — | 1.8% | Jan 7, 2003 |
40Plan | CVE-2012-6611No exploit | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Develpolycom · hdx system software · CWE-798 | Critical9.8 | — | 3.1% | Feb 10, 2020 |
38Monitor | CVE-2012-6610Weaponized | Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonpolycom · hdx video end points · CWE-78 | High8.8 | — | 10.9% | Jan 28, 2020 |
36Monitor | CVE-2021-41322No exploit | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password respolycom · vvx 400 firmware | High8.8 | — | 1.7% | Oct 4, 2021 |
35Monitor | CVE-2017-12857No exploit | Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 arpolycom · unified communications software · CWE-200 | High8.8 | — | 1.6% | Aug 25, 2017 |
35Monitor | CVE-2018-7565No exploit | CSRF exists on Polycom QDX 6000 devices.polycom · qdx 6000 firmware · CWE-352 | High8.8 | — | 0.5% | Mar 7, 2018 |
34Monitor | CVE-2019-12948No exploit | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Spolycom · unified communications software · CWE-749 | High8.3 | — | 1.7% | Jul 29, 2019 |
33Monitor | CVE-2019-14259No exploit | On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP addpolycom · obihai obi1022 firmware · CWE-78 | High8.0 | — | 2.8% | Aug 1, 2019 |
32Monitor | CVE-2007-3369No exploit | Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause apolycom · soundpoint ip 601 · CWE-119 | High7.8 | — | 2.2% | Jun 22, 2007 |
32Monitor | CVE-2007-3368No exploit | Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial polycom · soundpoint ip 650 | High7.8 | — | 1.8% | Jun 22, 2007 |
32Monitor | CVE-2006-5233No exploit | Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) viapolycom · soundpoint ip 301 | High7.8 | — | 1.8% | Oct 10, 2006 |
32Monitor | CVE-2015-4681Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwopolycom · realpresence resource manager · CWE-255 | High7.8 | — | 1.7% | Sep 19, 2017 |
31Monitor | CVE-2002-0628No exploit | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rempolycom · viewstation 128 · CWE-307 | High7.5 | — | 2.2% | Jan 7, 2003 |
31Monitor | CVE-2012-6609No exploit | Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attacpolycom · hdx video end points · CWE-22 | High7.5 | — | 2.1% | Jan 28, 2020 |
31Monitor | CVE-2015-8300No exploit | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\ppolycom · btoe connector · CWE-275 | High7.8 | — | 0.6% | Aug 28, 2017 |
30Monitor | CVE-2002-0627No exploit | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requpolycom · viewstation 128 | High7.5 | — | 1.6% | Jan 7, 2003 |
30Monitor | CVE-2018-12592No exploit | Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicpolycom · realpresence web suite · CWE-200 | High7.5 | — | 1.4% | Jun 20, 2018 |
28Monitor | CVE-2015-4682Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POpolycom · realpresence resource manager · CWE-200 | Medium6.5 | — | 5.2% | Sep 19, 2017 |
28Monitor | CVE-2015-4685Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scripolycom · realpresence resource manager · CWE-264 | High7.0 | — | 1.2% | Sep 19, 2017 |
28Monitor | CVE-2019-11355No exploit | An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.polycom · hdx system software · CWE-78 | High7.2 | — | 1.1% | Mar 12, 2020 |
27Monitor | CVE-2015-4684Proof of concept | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated upolycom · realpresence resource manager · CWE-255 | Medium6.5 | — | 4.9% | Sep 19, 2017 |
27Monitor | CVE-2018-10946No exploit | An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the adpolycom · realpresence debut firmware · CWE-200 | Medium6.8 | — | 0.5% | Jun 13, 2019 |
27Monitor | CVE-2019-10688No exploit | VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,polycom · unified communications software · CWE-798 | Medium6.8 | — | 0.3% | Apr 23, 2019 |
- CVE-2015-468341Plan
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges
CriticalCVSS 9.8Proof of conceptEPSS 7%polycom · realpresence resource managerSep 19, 2017
- CVE-2018-1512841Plan
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.
CriticalCVSS 9.8No exploitEPSS 5%polycom · group seriesMay 13, 2019
- CVE-2002-062641Plan
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthor
CriticalCVSS 10.0No exploitEPSS 2%polycom · viewstation 128Jan 7, 2003
- CVE-2012-661140Plan
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Devel
CriticalCVSS 9.8No exploitEPSS 3%polycom · hdx system softwareFeb 10, 2020
- CVE-2012-661038Monitor
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demon
HighCVSS 8.8WeaponizedEPSS 11%polycom · hdx video end pointsJan 28, 2020
- CVE-2021-4132236Monitor
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password res
HighCVSS 8.8No exploitEPSS 2%polycom · vvx 400 firmwareOct 4, 2021
- CVE-2017-1285735Monitor
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 ar
HighCVSS 8.8No exploitEPSS 2%polycom · unified communications softwareAug 25, 2017
- CVE-2018-756535Monitor
CSRF exists on Polycom QDX 6000 devices.
HighCVSS 8.8No exploitEPSS 0%polycom · qdx 6000 firmwareMar 7, 2018
- CVE-2019-1294834Monitor
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC S
HighCVSS 8.3No exploitEPSS 2%polycom · unified communications softwareJul 29, 2019
- CVE-2019-1425933Monitor
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP add
HighCVSS 8.0No exploitEPSS 3%polycom · obihai obi1022 firmwareAug 1, 2019
- CVE-2007-336932Monitor
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a
HighCVSS 7.8No exploitEPSS 2%polycom · soundpoint ip 601Jun 22, 2007
- CVE-2007-336832Monitor
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial
HighCVSS 7.8No exploitEPSS 2%polycom · soundpoint ip 650Jun 22, 2007
- CVE-2006-523332Monitor
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via
HighCVSS 7.8No exploitEPSS 2%polycom · soundpoint ip 301Oct 10, 2006
- CVE-2015-468132Monitor
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwo
HighCVSS 7.8Proof of conceptEPSS 2%polycom · realpresence resource managerSep 19, 2017
- CVE-2002-062831Monitor
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rem
HighCVSS 7.5No exploitEPSS 2%polycom · viewstation 128Jan 7, 2003
- CVE-2012-660931Monitor
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attac
HighCVSS 7.5No exploitEPSS 2%polycom · hdx video end pointsJan 28, 2020
- CVE-2015-830031Monitor
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\p
HighCVSS 7.8No exploitEPSS 1%polycom · btoe connectorAug 28, 2017
- CVE-2002-062730Monitor
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requ
HighCVSS 7.5No exploitEPSS 2%polycom · viewstation 128Jan 7, 2003
- CVE-2018-1259230Monitor
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explic
HighCVSS 7.5No exploitEPSS 1%polycom · realpresence web suiteJun 20, 2018
- CVE-2015-468228Monitor
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP PO
MediumCVSS 6.5Proof of conceptEPSS 5%polycom · realpresence resource managerSep 19, 2017
- CVE-2015-468528Monitor
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scri
HighCVSS 7.0Proof of conceptEPSS 1%polycom · realpresence resource managerSep 19, 2017
- CVE-2019-1135528Monitor
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.
HighCVSS 7.2No exploitEPSS 1%polycom · hdx system softwareMar 12, 2020
- CVE-2015-468427Monitor
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated u
MediumCVSS 6.5Proof of conceptEPSS 5%polycom · realpresence resource managerSep 19, 2017
- CVE-2018-1094627Monitor
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the ad
MediumCVSS 6.8No exploitEPSS 0%polycom · realpresence debut firmwareJun 13, 2019
- CVE-2019-1068827Monitor
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,
MediumCVSS 6.8No exploitEPSS 0%polycom · unified communications softwareApr 23, 2019