CVE-2025-43020
Severity CVSS v4.0:
MEDIUM
Type:
CWE-78
OS Command Injections
Publication date:
22/07/2025
Last modified:
02/10/2025
Description
A potential command<br />
injection vulnerability has been identified in the Poly Clariti Manager for<br />
versions prior to 10.12.2. The vulnerability could allow a privileged user<br />
to submit arbitrary input. HP has addressed the issue in the latest software update.
Impact
Base Score 4.0
5.70
Severity 4.0
MEDIUM
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:hp:poly_clariti_manager:*:*:*:*:*:*:*:* | 10.12.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



