Записи Poly
13 опубликованных записей вендора poly.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-404 Improper Resource Shutdown or Release1
- CWE-620 Unverified Password Change1
- CWE-693 Protection Mechanism Failure1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-26479Эксплойта нет | An issue was discovered in Poly EagleEye Director II before 2.2.2.1.poly · eagleeye director ii firmware · CWE-863 | Критическая9,8 | — | 2,1 % | 17 июл. 2022 г. |
36Наблюдать | CVE-2018-17875Эксплойта нет | A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commandspoly · trio 8800 firmware | Высокая8,8 | — | 2,7 % | 28 дек. 2021 г. |
35Наблюдать | CVE-2022-26482Эксплойта нет | An issue was discovered in Poly EagleEye Director II before 2.2.2.1.poly · eagleeye director ii firmware · CWE-78 | Высокая7,2 | — | 22,8 % | 17 июл. 2022 г. |
35Наблюдать | CVE-2022-26481Эксплойта нет | An issue was discovered in Poly Studio before 3.7.0.poly · studio x30 firmware · CWE-78 | Высокая8,8 | — | 1,5 % | 17 июл. 2022 г. |
30Наблюдать | CVE-2023-4463Эксплойта нет | Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of servicepoly · ccx 400 firmware · CWE-404 | Высокая7,5 | — | 1,0 % | 29 дек. 2023 г. |
30Наблюдать | CVE-2023-4468Эксплойта нет | Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorizationpoly · trio 8800 firmware · CWE-862 | Высокая7,6 | — | 0,3 % | 29 дек. 2023 г. |
29Наблюдать | CVE-2023-4464Эксплойта нет | Poly VVX 601 Diagnostic Telnet Mode os command injectionpoly · ccx 400 firmware · CWE-78 | Высокая7,2 | — | 3,3 % | 29 дек. 2023 г. |
29Наблюдать | CVE-2021-37145Эксплойта нет | A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attackerpoly · cx5500 firmware · CWE-77 | Высокая7,2 | — | 2,0 % | 7 сент. 2021 г. |
26Наблюдать | CVE-2023-4465Эксплойта нет | Poly VVX 601 Configuration File Import unverified password changepoly · ccx 400 firmware · CWE-620 | Средняя6,5 | — | 0,5 % | 29 дек. 2023 г. |
26Наблюдать | CVE-2023-4467Эксплойта нет | Poly Trio 8800 Test Automation Mode backdoorpoly · trio 8800 firmware · CWE-912 | Средняя6,6 | — | 0,3 % | 29 дек. 2023 г. |
23Наблюдать | CVE-2023-4462Эксплойта нет | Poly VVX 601 Web Configuration Application random valuespoly · ccx 400 firmware · CWE-330 | Средняя5,9 | — | 0,9 % | 29 дек. 2023 г. |
21Наблюдать | CVE-2023-24282Эксплойта нет | An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.poly · trio 8800 firmware · CWE-79 | Средняя5,4 | — | 0,5 % | 8 мар. 2023 г. |
19Наблюдать | CVE-2023-4466Эксплойта нет | Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanismpoly · ccx 400 firmware · CWE-693 | Средняя4,9 | — | 0,5 % | 29 дек. 2023 г. |
- CVE-2022-2647940В плане
An issue was discovered in Poly EagleEye Director II before 2.2.2.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %poly · eagleeye director ii firmware17 июл. 2022 г.
- CVE-2018-1787536Наблюдать
A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %poly · trio 8800 firmware28 дек. 2021 г.
- CVE-2022-2648235Наблюдать
An issue was discovered in Poly EagleEye Director II before 2.2.2.1.
ВысокаяCVSS 7,2Эксплойта нетEPSS 23 %poly · eagleeye director ii firmware17 июл. 2022 г.
- CVE-2022-2648135Наблюдать
An issue was discovered in Poly Studio before 3.7.0.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %poly · studio x30 firmware17 июл. 2022 г.
- CVE-2023-446330Наблюдать
Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of service
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %poly · ccx 400 firmware29 дек. 2023 г.
- CVE-2023-446830Наблюдать
Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %poly · trio 8800 firmware29 дек. 2023 г.
- CVE-2023-446429Наблюдать
Poly VVX 601 Diagnostic Telnet Mode os command injection
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %poly · ccx 400 firmware29 дек. 2023 г.
- CVE-2021-3714529Наблюдать
A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker
ВысокаяCVSS 7,2Эксплойта нетEPSS 2 %poly · cx5500 firmware7 сент. 2021 г.
- CVE-2023-446526Наблюдать
Poly VVX 601 Configuration File Import unverified password change
СредняяCVSS 6,5Эксплойта нетEPSS 0 %poly · ccx 400 firmware29 дек. 2023 г.
- CVE-2023-446726Наблюдать
Poly Trio 8800 Test Automation Mode backdoor
СредняяCVSS 6,6Эксплойта нетEPSS 0 %poly · trio 8800 firmware29 дек. 2023 г.
- CVE-2023-446223Наблюдать
Poly VVX 601 Web Configuration Application random values
СредняяCVSS 5,9Эксплойта нетEPSS 1 %poly · ccx 400 firmware29 дек. 2023 г.
- CVE-2023-2428221Наблюдать
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %poly · trio 8800 firmware8 мар. 2023 г.
- CVE-2023-446619Наблюдать
Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanism
СредняяCVSS 4,9Эксплойта нетEPSS 1 %poly · ccx 400 firmware29 дек. 2023 г.