CVE-2025-14432
Severity CVSS v4.0:
HIGH
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
16/12/2025
Last modified:
18/12/2025
Description
In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.
Impact
Base Score 4.0
8.10
Severity 4.0
HIGH
Base Score 3.x
4.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:hp:poly_videoos:*:*:*:*:*:*:*:* | 4.6.1-444242 (excluding) | |
| cpe:2.3:h:hp:poly_eagleeye_cube:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_eagleeye_iv:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_a2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_e60:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_e70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_g62:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_g7500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_usb:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x30:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x32:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x52:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x70:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:hp:poly_studio_x72:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



