CVE-2021-37145
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
07/09/2021
Last modified:
04/08/2024
Description
A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:poly:cx5500_firmware:1.3.5:*:*:*:*:*:*:* | ||
cpe:2.3:h:poly:cx5500:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:poly:cx5100_firmware:1.3.5:*:*:*:*:*:*:* | ||
cpe:2.3:h:poly:cx5100:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page