Polycom kayıtları
polycom üreticisine ait 39 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,6
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-255 Credentials Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
39 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2015-4683Kavram kanıtı | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privilegespolycom · realpresence resource manager · CWE-264 | Kritik9,8 | — | %6,9 | 19 Eyl 2017 |
41Planlayın | CVE-2018-15128İstismar yok | An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.polycom · group series · CWE-119 | Kritik9,8 | — | %5,2 | 13 May 2019 |
41Planlayın | CVE-2002-0626İstismar yok | Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorpolycom · viewstation 128 | Kritik10,0 | — | %1,8 | 7 Oca 2003 |
40Planlayın | CVE-2012-6611İstismar yok | An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Develpolycom · hdx system software · CWE-798 | Kritik9,8 | — | %3,1 | 10 Şub 2020 |
38İzleyin | CVE-2012-6610Silahlaştırılmış | Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonpolycom · hdx video end points · CWE-78 | Yüksek8,8 | — | %10,9 | 28 Oca 2020 |
36İzleyin | CVE-2021-41322İstismar yok | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password respolycom · vvx 400 firmware | Yüksek8,8 | — | %1,7 | 4 Eki 2021 |
35İzleyin | CVE-2017-12857İstismar yok | Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 arpolycom · unified communications software · CWE-200 | Yüksek8,8 | — | %1,6 | 25 Ağu 2017 |
35İzleyin | CVE-2018-7565İstismar yok | CSRF exists on Polycom QDX 6000 devices.polycom · qdx 6000 firmware · CWE-352 | Yüksek8,8 | — | %0,5 | 7 Mar 2018 |
34İzleyin | CVE-2019-12948İstismar yok | A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Spolycom · unified communications software · CWE-749 | Yüksek8,3 | — | %1,7 | 29 Tem 2019 |
33İzleyin | CVE-2019-14259İstismar yok | On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP addpolycom · obihai obi1022 firmware · CWE-78 | Yüksek8,0 | — | %2,8 | 1 Ağu 2019 |
32İzleyin | CVE-2007-3369İstismar yok | Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause apolycom · soundpoint ip 601 · CWE-119 | Yüksek7,8 | — | %2,2 | 22 Haz 2007 |
32İzleyin | CVE-2007-3368İstismar yok | Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial polycom · soundpoint ip 650 | Yüksek7,8 | — | %1,8 | 22 Haz 2007 |
32İzleyin | CVE-2006-5233İstismar yok | Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) viapolycom · soundpoint ip 301 | Yüksek7,8 | — | %1,8 | 10 Eki 2006 |
32İzleyin | CVE-2015-4681Kavram kanıtı | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwopolycom · realpresence resource manager · CWE-255 | Yüksek7,8 | — | %1,7 | 19 Eyl 2017 |
31İzleyin | CVE-2002-0628İstismar yok | The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rempolycom · viewstation 128 · CWE-307 | Yüksek7,5 | — | %2,2 | 7 Oca 2003 |
31İzleyin | CVE-2012-6609İstismar yok | Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attacpolycom · hdx video end points · CWE-22 | Yüksek7,5 | — | %2,1 | 28 Oca 2020 |
31İzleyin | CVE-2015-8300İstismar yok | Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\ppolycom · btoe connector · CWE-275 | Yüksek7,8 | — | %0,6 | 28 Ağu 2017 |
30İzleyin | CVE-2002-0627İstismar yok | The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requpolycom · viewstation 128 | Yüksek7,5 | — | %1,6 | 7 Oca 2003 |
30İzleyin | CVE-2018-12592İstismar yok | Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicpolycom · realpresence web suite · CWE-200 | Yüksek7,5 | — | %1,4 | 20 Haz 2018 |
28İzleyin | CVE-2015-4682Kavram kanıtı | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POpolycom · realpresence resource manager · CWE-200 | Orta6,5 | — | %5,2 | 19 Eyl 2017 |
28İzleyin | CVE-2015-4685Kavram kanıtı | Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scripolycom · realpresence resource manager · CWE-264 | Yüksek7,0 | — | %1,2 | 19 Eyl 2017 |
28İzleyin | CVE-2019-11355İstismar yok | An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.polycom · hdx system software · CWE-78 | Yüksek7,2 | — | %1,1 | 12 Mar 2020 |
27İzleyin | CVE-2015-4684Kavram kanıtı | Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated upolycom · realpresence resource manager · CWE-255 | Orta6,5 | — | %4,9 | 19 Eyl 2017 |
27İzleyin | CVE-2018-10946İstismar yok | An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the adpolycom · realpresence debut firmware · CWE-200 | Orta6,8 | — | %0,5 | 13 Haz 2019 |
27İzleyin | CVE-2019-10688İstismar yok | VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,polycom · unified communications software · CWE-798 | Orta6,8 | — | %0,3 | 23 Nis 2019 |
- CVE-2015-468341Planlayın
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges
KritikCVSS 9,8Kavram kanıtıEPSS %7polycom · realpresence resource manager19 Eyl 2017
- CVE-2018-1512841Planlayın
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier.
KritikCVSS 9,8İstismar yokEPSS %5polycom · group series13 May 2019
- CVE-2002-062641Planlayın
Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthor
KritikCVSS 10,0İstismar yokEPSS %2polycom · viewstation 1287 Oca 2003
- CVE-2012-661140Planlayın
An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Devel
KritikCVSS 9,8İstismar yokEPSS %3polycom · hdx system software10 Şub 2020
- CVE-2012-661038İzleyin
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demon
YüksekCVSS 8,8SilahlaştırılmışEPSS %11polycom · hdx video end points28 Oca 2020
- CVE-2021-4132236İzleyin
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password res
YüksekCVSS 8,8İstismar yokEPSS %2polycom · vvx 400 firmware4 Eki 2021
- CVE-2017-1285735İzleyin
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 ar
YüksekCVSS 8,8İstismar yokEPSS %2polycom · unified communications software25 Ağu 2017
- CVE-2018-756535İzleyin
CSRF exists on Polycom QDX 6000 devices.
YüksekCVSS 8,8İstismar yokEPSS %0polycom · qdx 6000 firmware7 Mar 2018
- CVE-2019-1294834İzleyin
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC S
YüksekCVSS 8,3İstismar yokEPSS %2polycom · unified communications software29 Tem 2019
- CVE-2019-1425933İzleyin
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP add
YüksekCVSS 8,0İstismar yokEPSS %3polycom · obihai obi1022 firmware1 Ağu 2019
- CVE-2007-336932İzleyin
Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a
YüksekCVSS 7,8İstismar yokEPSS %2polycom · soundpoint ip 60122 Haz 2007
- CVE-2007-336832İzleyin
Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial
YüksekCVSS 7,8İstismar yokEPSS %2polycom · soundpoint ip 65022 Haz 2007
- CVE-2006-523332İzleyin
Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via
YüksekCVSS 7,8İstismar yokEPSS %2polycom · soundpoint ip 30110 Eki 2006
- CVE-2015-468132İzleyin
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwo
YüksekCVSS 7,8Kavram kanıtıEPSS %2polycom · realpresence resource manager19 Eyl 2017
- CVE-2002-062831İzleyin
The Telnet service for Polycom ViewStation before 7.2.4 does not restrict the number of failed login attempts, which makes it easier for rem
YüksekCVSS 7,5İstismar yokEPSS %2polycom · viewstation 1287 Oca 2003
- CVE-2012-660931İzleyin
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attac
YüksekCVSS 7,5İstismar yokEPSS %2polycom · hdx video end points28 Oca 2020
- CVE-2015-830031İzleyin
Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\p
YüksekCVSS 7,8İstismar yokEPSS %1polycom · btoe connector28 Ağu 2017
- CVE-2002-062730İzleyin
The Web server for Polycom ViewStation before 7.2.4 allows remote attackers to bypass authentication and read files via Unicode encoded requ
YüksekCVSS 7,5İstismar yokEPSS %2polycom · viewstation 1287 Oca 2003
- CVE-2018-1259230İzleyin
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explic
YüksekCVSS 7,5İstismar yokEPSS %1polycom · realpresence web suite20 Haz 2018
- CVE-2015-468228İzleyin
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP PO
OrtaCVSS 6,5Kavram kanıtıEPSS %5polycom · realpresence resource manager19 Eyl 2017
- CVE-2015-468528İzleyin
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a scri
YüksekCVSS 7,0Kavram kanıtıEPSS %1polycom · realpresence resource manager19 Eyl 2017
- CVE-2019-1135528İzleyin
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13.
YüksekCVSS 7,2İstismar yokEPSS %1polycom · hdx system software12 Mar 2020
- CVE-2015-468427İzleyin
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated u
OrtaCVSS 6,5Kavram kanıtıEPSS %5polycom · realpresence resource manager19 Eyl 2017
- CVE-2018-1094627İzleyin
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the ad
OrtaCVSS 6,8İstismar yokEPSS %0polycom · realpresence debut firmware13 Haz 2019
- CVE-2019-1068827İzleyin
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1,
OrtaCVSS 6,8İstismar yokEPSS %0polycom · unified communications software23 Nis 2019