Vulnerabilities > Polycom > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-06-24 | CVE-2019-10689 | Improper Authentication vulnerability in Polycom products VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information. | 6.5 |
2019-06-13 | CVE-2018-10946 | Information Exposure vulnerability in Polycom Realpresence Debut Firmware An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI. | 6.8 |
2019-04-23 | CVE-2019-10688 | Use of Hard-coded Credentials vulnerability in Polycom products VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device. | 6.8 |
2018-11-15 | CVE-2018-14935 | Cross-site Scripting vulnerability in Polycom Trio 8500 Firmware 5.5.2/5.5.3 The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS. | 6.1 |
2018-11-15 | CVE-2018-14934 | Incorrect Permission Assignment for Critical Resource vulnerability in Polycom Trio 8500 Firmware 5.5.2/5.5.3 The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. | 6.5 |
2018-10-24 | CVE-2018-18568 | Improper Certificate Validation vulnerability in Polycom Unified Communications Software Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business. | 5.9 |
2018-10-24 | CVE-2018-18566 | Information Exposure vulnerability in Polycom Unified Communications Software The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business. | 5.3 |
2018-03-07 | CVE-2018-7564 | Cross-site Scripting vulnerability in Polycom QDX 6000 Firmware Stored XSS exists on Polycom QDX 6000 devices. | 6.1 |
2017-09-19 | CVE-2015-4684 | Credentials Management vulnerability in Polycom Realpresence Resource Manager Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to read arbitrary files via a .. | 6.5 |
2017-09-19 | CVE-2015-4682 | Information Exposure vulnerability in Polycom Realpresence Resource Manager Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST request to PlcmRmWeb/JConfigManager. | 6.5 |