CVE-2019-10689

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
24/06/2019
Last modified:
27/06/2019

Description

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:polycom:better_together_over_ethernet_connector:*:*:*:*:*:*:*:* 3.9.1 (including)
cpe:2.3:a:polycom:unified_communications_software:*:*:*:*:*:*:*:* 5.9.2 (including)