CVE-2017-12857

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/08/2017
Last modified:
20/04/2025

Description

Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could contain an administrator's password or other sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 4.0.11 (including)
cpe:2.3:h:polycom:soundstation_ip:-:*:*:*:*:*:*:*
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.4.6 (including)
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.5.1 (including)
cpe:2.3:h:polycom:vvx:-:*:*:*:*:*:*:*
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.4.4 (including)
cpe:2.3:h:polycom:realpresence_trio:-:*:*:*:*:*:*:*