CVE-2019-12948

Severity CVSS v4.0:
Pending analysis
Type:
CWE-749 Exposed Dangerous Method or Function
Publication date:
29/07/2019
Last modified:
06/08/2019

Description

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.8.5.1256 (excluding)
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.9.3 (including) 5.9.3.2857 (excluding)
cpe:2.3:o:polycom:unified_communications_software:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.0.4839 (excluding)
cpe:2.3:h:polycom:c12:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:c16:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:c8:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx150:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx201:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx250:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx301:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx311:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx350:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx401:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx411:-:*:*:*:*:*:*:*
cpe:2.3:h:polycom:vvx450:-:*:*:*:*:*:*:*