Записи Polycom
39 опубликованных записей вендора polycom.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,6 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
39 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2015-4683Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privilegespolycom · realpresence resource manager · CWE-264 | Критическая9,8 | — | 6,9 % | 19 сент. 2017 г. |
41В плане | CVE-2018-15128Эксплойта нет | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.polycom · group series · CWE-119 | Критическая9,8 | — | 5,2 % | 13 мая 2019 г. |
41В плане | CVE-2002-0626Эксплойта нет | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorpolycom · viewstation 128 | Критическая10,0 | — | 1,8 % | 7 янв. 2003 г. |
40В плане | CVE-2012-6611Эксплойта нет | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Develpolycom · hdx system software · CWE-798 | Критическая9,8 | — | 3,1 % | 10 февр. 2020 г. |
38Наблюдать | CVE-2012-6610Готовый эксплойт | Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonpolycom · hdx video end points · CWE-78 | Высокая8,8 | — | 10,9 % | 28 янв. 2020 г. |
36Наблюдать | CVE-2021-41322Эксплойта нет | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password respolycom · vvx 400 firmware | Высокая8,8 | — | 1,7 % | 4 окт. 2021 г. |
35Наблюдать | CVE-2017-12857Эксплойта нет | Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 arpolycom · unified communications software · CWE-200 | Высокая8,8 | — | 1,6 % | 25 авг. 2017 г. |
35Наблюдать | CVE-2018-7565Эксплойта нет | CSRF exists on Polycom QDX 6000 devices.polycom · qdx 6000 firmware · CWE-352 | Высокая8,8 | — | 0,5 % | 7 мар. 2018 г. |
34Наблюдать | CVE-2019-12948Эксплойта нет | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Spolycom · unified communications software · CWE-749 | Высокая8,3 | — | 1,7 % | 29 июл. 2019 г. |
33Наблюдать | CVE-2019-14259Эксплойта нет | On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP addpolycom · obihai obi1022 firmware · CWE-78 | Высокая8,0 | — | 2,8 % | 1 авг. 2019 г. |
32Наблюдать | CVE-2007-3369Эксплойта нет | Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause apolycom · soundpoint ip 601 · CWE-119 | Высокая7,8 | — | 2,2 % | 22 июн. 2007 г. |
32Наблюдать | CVE-2007-3368Эксплойта нет | Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial polycom · soundpoint ip 650 | Высокая7,8 | — | 1,8 % | 22 июн. 2007 г. |
32Наблюдать | CVE-2006-5233Эксплойта нет | Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) viapolycom · soundpoint ip 301 | Высокая7,8 | — | 1,8 % | 10 окт. 2006 г. |
32Наблюдать | CVE-2015-4681Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwopolycom · realpresence resource manager · CWE-255 | Высокая7,8 | — | 1,7 % | 19 сент. 2017 г. |
31Наблюдать | CVE-2002-0628Эксплойта нет | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rempolycom · viewstation 128 · CWE-307 | Высокая7,5 | — | 2,2 % | 7 янв. 2003 г. |
31Наблюдать | CVE-2012-6609Эксплойта нет | Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attacpolycom · hdx video end points · CWE-22 | Высокая7,5 | — | 2,1 % | 28 янв. 2020 г. |
31Наблюдать | CVE-2015-8300Эксплойта нет | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\ppolycom · btoe connector · CWE-275 | Высокая7,8 | — | 0,6 % | 28 авг. 2017 г. |
30Наблюдать | CVE-2002-0627Эксплойта нет | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requpolycom · viewstation 128 | Высокая7,5 | — | 1,6 % | 7 янв. 2003 г. |
30Наблюдать | CVE-2018-12592Эксплойта нет | Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicpolycom · realpresence web suite · CWE-200 | Высокая7,5 | — | 1,4 % | 20 июн. 2018 г. |
28Наблюдать | CVE-2015-4682Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POpolycom · realpresence resource manager · CWE-200 | Средняя6,5 | — | 5,2 % | 19 сент. 2017 г. |
28Наблюдать | CVE-2015-4685Proof of concept | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scripolycom · realpresence resource manager · CWE-264 | Высокая7,0 | — | 1,2 % | 19 сент. 2017 г. |
28Наблюдать | CVE-2019-11355Эксплойта нет | An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.polycom · hdx system software · CWE-78 | Высокая7,2 | — | 1,1 % | 12 мар. 2020 г. |
27Наблюдать | CVE-2015-4684Proof of concept | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated upolycom · realpresence resource manager · CWE-255 | Средняя6,5 | — | 4,9 % | 19 сент. 2017 г. |
27Наблюдать | CVE-2018-10946Эксплойта нет | An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the adpolycom · realpresence debut firmware · CWE-200 | Средняя6,8 | — | 0,5 % | 13 июн. 2019 г. |
27Наблюдать | CVE-2019-10688Эксплойта нет | VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,polycom · unified communications software · CWE-798 | Средняя6,8 | — | 0,3 % | 23 апр. 2019 г. |
- CVE-2015-468341В плане
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges
КритическаяCVSS 9,8Proof of conceptEPSS 7 %polycom · realpresence resource manager19 сент. 2017 г.
- CVE-2018-1512841В плане
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %polycom · group series13 мая 2019 г.
- CVE-2002-062641В плане
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthor
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %polycom · viewstation 1287 янв. 2003 г.
- CVE-2012-661140В плане
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Devel
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %polycom · hdx system software10 февр. 2020 г.
- CVE-2012-661038Наблюдать
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demon
ВысокаяCVSS 8,8Готовый эксплойтEPSS 11 %polycom · hdx video end points28 янв. 2020 г.
- CVE-2021-4132236Наблюдать
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password res
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %polycom · vvx 400 firmware4 окт. 2021 г.
- CVE-2017-1285735Наблюдать
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 ar
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %polycom · unified communications software25 авг. 2017 г.
- CVE-2018-756535Наблюдать
CSRF exists on Polycom QDX 6000 devices.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %polycom · qdx 6000 firmware7 мар. 2018 г.
- CVE-2019-1294834Наблюдать
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC S
ВысокаяCVSS 8,3Эксплойта нетEPSS 2 %polycom · unified communications software29 июл. 2019 г.
- CVE-2019-1425933Наблюдать
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP add
ВысокаяCVSS 8,0Эксплойта нетEPSS 3 %polycom · obihai obi1022 firmware1 авг. 2019 г.
- CVE-2007-336932Наблюдать
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %polycom · soundpoint ip 60122 июн. 2007 г.
- CVE-2007-336832Наблюдать
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %polycom · soundpoint ip 65022 июн. 2007 г.
- CVE-2006-523332Наблюдать
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %polycom · soundpoint ip 30110 окт. 2006 г.
- CVE-2015-468132Наблюдать
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwo
ВысокаяCVSS 7,8Proof of conceptEPSS 2 %polycom · realpresence resource manager19 сент. 2017 г.
- CVE-2002-062831Наблюдать
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rem
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %polycom · viewstation 1287 янв. 2003 г.
- CVE-2012-660931Наблюдать
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attac
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %polycom · hdx video end points28 янв. 2020 г.
- CVE-2015-830031Наблюдать
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\p
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %polycom · btoe connector28 авг. 2017 г.
- CVE-2002-062730Наблюдать
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requ
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %polycom · viewstation 1287 янв. 2003 г.
- CVE-2018-1259230Наблюдать
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explic
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %polycom · realpresence web suite20 июн. 2018 г.
- CVE-2015-468228Наблюдать
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP PO
СредняяCVSS 6,5Proof of conceptEPSS 5 %polycom · realpresence resource manager19 сент. 2017 г.
- CVE-2015-468528Наблюдать
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scri
ВысокаяCVSS 7,0Proof of conceptEPSS 1 %polycom · realpresence resource manager19 сент. 2017 г.
- CVE-2019-1135528Наблюдать
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %polycom · hdx system software12 мар. 2020 г.
- CVE-2015-468427Наблюдать
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated u
СредняяCVSS 6,5Proof of conceptEPSS 5 %polycom · realpresence resource manager19 сент. 2017 г.
- CVE-2018-1094627Наблюдать
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the ad
СредняяCVSS 6,8Эксплойта нетEPSS 0 %polycom · realpresence debut firmware13 июн. 2019 г.
- CVE-2019-1068827Наблюдать
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,
СредняяCVSS 6,8Эксплойта нетEPSS 0 %polycom · unified communications software23 апр. 2019 г.