Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vvx 400 Firmware HIGH 8.8
CVE-2021-41322

Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset proces…

No fix yet
Fix from $1,950 2021-10-04
Hdx System Software HIGH 7.2
CVE-2019-11355

An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upl…

Fix: after 3.1.13
Fix from $1,950 2020-03-12
Hdx System Software CRITICAL 9.8
CVE-2012-6611

An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Pl…

Fix: after 3.0.5
Fix from $2,300 2020-02-10
Hdx Video End Points HIGH 8.8
CVE-2012-6610EPSS 11%

Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated b…

Fix: 2.7.1.j / 3.0.4+
Fix from $1,950 2020-01-28
Hdx Video End Points HIGH 7.5
CVE-2012-6609

Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to r…

Fix: 2.7.1.j / 3.0.4+
Fix from $1,950 2020-01-28
Obihai Obi1022 Firmware HIGH 8.0
CVE-2019-14259

On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address fiel…

No fix yet
Fix from $1,950 2019-08-01
Unified Communications Software HIGH 8.3
CVE-2019-12948

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, …

Fix: 4.0.14.1580 / 5.8.5.1256+
Fix from $1,950 2019-07-29
Better Together Over Ethernet Connector MEDIUM 6.5
CVE-2019-10689

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier p…

Fix: after 5.9.2
Fix from $1,600 2019-06-24
Realpresence Debut Firmware MEDIUM 6.8
CVE-2018-10946

An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user'…

Fix: 1.3.0-66872+
Fix from $1,600 2019-06-13
Group Series CRITICAL 9.8
CVE-2018-15128EPSS 5%

An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vuln…

Fix: after 6.1.6.1
Fix from $2,300 2019-05-13
Unified Communications Software MEDIUM 6.8
CVE-2019-10688

VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard…

Fix: after 5.8.0
Fix from $1,600 2019-04-23
Trio 8500 Firmware MEDIUM 6.5
CVE-2018-14934

The Bluetooth subsystem on Polycom Trio devices with software before 5.5.4 has Incorrect Access Control. An attacker can connect without authenticati…

Fix: 5.5.4+
Fix from $1,600 2018-11-15
Trio 8500 Firmware MEDIUM 6.1
CVE-2018-14935

The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.

Fix: 5.5.4+
Fix from $1,600 2018-11-15
Unified Communications Software MEDIUM 5.9
CVE-2018-18568

Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging f…

Fix: after 5.8.0.12848
Fix from $1,600 2018-10-24
Unified Communications Software MEDIUM 5.3
CVE-2018-18566

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information…

Fix: after 5.8.0.12848
Fix from $1,600 2018-10-24
Realpresence Web Suite HIGH 7.5
CVE-2018-12592

Polycom RealPresence Web Suite before 2.2.0 does not block a user's video for a few seconds upon joining a meeting (when the user has explicitly chos…

Fix: 2.2.0+
Fix from $1,950 2018-06-20
Qdx 6000 Firmware HIGH 8.8
CVE-2018-7565

CSRF exists on Polycom QDX 6000 devices.

No fix yet
Fix from $1,950 2018-03-07
Qdx 6000 Firmware MEDIUM 6.1
CVE-2018-7564

Stored XSS exists on Polycom QDX 6000 devices.

Mitigation only
Fix from $1,600 2018-03-07
Realpresence Resource Manager CRITICAL 9.8
CVE-2015-4683EPSS 7%

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by lever…

Fix: after 8.3.2
Fix from $2,300 2017-09-19
Realpresence Resource Manager HIGH 7.8
CVE-2015-4681

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.

Fix: after 8.3.2
Fix from $1,950 2017-09-19
Realpresence Resource Manager HIGH 7.0
CVE-2015-4685

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users with access to the plcm account to gain privileges via a script in /va…

Fix: after 8.3.2
Fix from $1,950 2017-09-19
Realpresence Resource Manager MEDIUM 6.5
CVE-2015-4682EPSS 5%

Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows remote authenticated users to obtain the installation path via an HTTP POST reques…

Fix: after 8.3.2
Fix from $1,600 2017-09-19
Realpresence Resource Manager MEDIUM 6.5
CVE-2015-4684

Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) remote authenticated users to r…

Fix: after 8.3.2
Fix from $1,600 2017-09-19
Btoe Connector HIGH 7.8
CVE-2015-8300

Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesr…

Fix: after 2.3.0
Fix from $1,950 2017-08-28
Unified Communications Software HIGH 8.8
CVE-2017-12857

Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affecte…

Fix: after 5.5.1
Fix from $1,950 2017-08-25
Soundpoint Ip 650 HIGH 7.8
CVE-2007-3368

Buffer overflow in the HTTP server on the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ allows remote attackers to cause a denial of servic…

Mitigation only
Fix from $1,950 2007-06-22
Soundpoint Ip 601 HIGH 7.8
CVE-2007-3369

Buffer overflow in the Polycom SoundPoint IP 601 SIP phone with BootROM 3.0.x+ and SIP version 1.6.3.0067 allows remote attackers to cause a denial o…

Mitigation only
Fix from $1,950 2007-06-22
Soundpoint Ip 301 HIGH 7.8
CVE-2006-5233

Polycom SoundPoint IP 301 VoIP Desktop Phone, firmware version 1.4.1.0040, allows remote attackers to cause a denial of service (reboot) via (1) a lo…

Mitigation only
Fix from $1,950 2006-10-11
Mgc 100 MEDIUM 5.0
CVE-2003-0556

Polycom MGC 25 allows remote attackers to cause a denial of service (crash) via a large number of "user" requests to the control port 5003, as demons…

Mitigation only
Fix from $1,600 2003-08-18
Viewstation 128 HIGH 10.0
CVE-2002-0626

Polycom ViewStation before 7.2.4 has a default null password for the administrator account, which allows arbitrary users to conduct unauthorized acti…

Patch available
Fix from $1,950 2003-01-07