Vulnerabilities > Polycom > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-01-28 CVE-2012-6609 Path Traversal vulnerability in Polycom HDX Video END Points and UC APL
Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a ..
network
low complexity
polycom CWE-22
5.0
2019-07-29 CVE-2019-12948 Exposed Dangerous Method or Function vulnerability in Polycom products
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
network
low complexity
polycom CWE-749
6.5
2019-04-23 CVE-2019-10688 Use of Hard-coded Credentials vulnerability in Polycom products
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.
local
low complexity
polycom CWE-798
4.6
2018-11-15 CVE-2018-14935 Cross-site Scripting vulnerability in Polycom Trio 8500 Firmware
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
network
polycom CWE-79
4.3
2018-10-24 CVE-2018-18568 Improper Certificate Validation vulnerability in Polycom Unified Communications Software
Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.
network
polycom CWE-295
4.3
2018-10-24 CVE-2018-18566 Information Exposure vulnerability in Polycom Unified Communications Software
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
network
low complexity
polycom CWE-200
5.0
2018-06-20 CVE-2018-12592 Information Exposure vulnerability in Polycom Realpresence web Suite
Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chosen to turn off the video using a specific option).
network
low complexity
polycom CWE-200
5.0
2018-03-07 CVE-2018-7565 Cross-Site Request Forgery (CSRF) vulnerability in Polycom QDX 6000 Firmware
CSRF exists on Polycom QDX 6000 devices.
network
polycom CWE-352
6.8
2018-03-07 CVE-2018-7564 Cross-site Scripting vulnerability in Polycom QDX 6000 Firmware
Stored XSS exists on Polycom QDX 6000 devices.
network
polycom CWE-79
4.3
2017-09-19 CVE-2015-4685 Permissions, Privileges, and Access Controls vulnerability in Polycom Realpresence Resource Manager
Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /var/polycom/cma/upgrade/scripts, related to a sudo misconfiguration.
4.4