Search

Find a vulnerability

Search criteria

    6 vulnerabilities by Poly

    CVE-2024-9579 (GCVE-0-2024-9579)

    Vulnerability from nvd – Published: 2024-11-05 16:22 – Updated: 2024-11-05 19:32
    VLAI
    Title
    Certain Poly Video Conference Devices – Potential Remote Code Execution
    Summary
    A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-05 19:13 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    HP, Inc. Certain Poly Video Conference Devices Affected: See HP security bulletin reference for affected versions
    Create a notification for this product.
    poly tc8_firmware Affected: 0 , < 6.3.2 (custom)
        cpe:2.3:o:poly:tc8_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly tc10_firmware Affected: 0 , < 6.3.2 (custom)
        cpe:2.3:o:poly:tc10_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly g7500_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x30_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x50_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x70_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x52_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x52_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_g62_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_g62_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:poly:tc8_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc8_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "6.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:tc10_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc10_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "6.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "g7500_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x30_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x50_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x70_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x52_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x52_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_g62_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_g62_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9579",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-05T19:13:45.885761Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-05T19:32:25.537Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Certain Poly Video Conference Devices",
              "vendor": "HP, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "See HP security bulletin reference for affected versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.\u003c/span\u003e"
                }
              ],
              "value": "A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-05T16:22:01.465Z",
            "orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
            "shortName": "hp"
          },
          "references": [
            {
              "url": "https://support.hp.com/us-en/document/ish_11536495-11536533-16/hpsbpy03900"
            }
          ],
          "source": {
            "advisory": "HPSBPY03900",
            "discovery": "UNKNOWN"
          },
          "title": "Certain Poly Video Conference Devices \u2013 Potential Remote Code Execution",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
        "assignerShortName": "hp",
        "cveId": "CVE-2024-9579",
        "datePublished": "2024-11-05T16:22:01.465Z",
        "dateReserved": "2024-10-07T13:24:15.881Z",
        "dateUpdated": "2024-11-05T19:32:25.537Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6147 (GCVE-0-2024-6147)

    Vulnerability from nvd – Published: 2024-06-20 20:11 – Updated: 2024-08-01 21:33
    VLAI
    Title
    Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability
    Summary
    Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 19:21 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Vendor Product Version
    Poly Plantronics Hub Affected: 3.24.2 Build 36336
    Create a notification for this product.
    plantronics plantronics_hub Affected: 3.24.2 Build 36336
        cpe:2.3:a:plantronics:plantronics_hub:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    Date Public
    2024-06-18 23:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:plantronics:plantronics_hub:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "plantronics_hub",
                "vendor": "plantronics",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.24.2 Build 36336"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6147",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T19:21:00.721267Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-26T19:40:03.741Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:33:04.947Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ZDI-24-802",
                "tags": [
                  "x_research-advisory",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-802/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Plantronics Hub",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.24.2 Build 36336"
                }
              ]
            }
          ],
          "dateAssigned": "2024-06-18T21:11:49.104Z",
          "datePublic": "2024-06-18T23:32:18.515Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-20T20:11:52.626Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-24-802",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-802/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Michael DePlante (@izobashi) of Trend Micro\u0027s Zero Day Initiative"
          },
          "title": "Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2024-6147",
        "datePublished": "2024-06-20T20:11:52.626Z",
        "dateReserved": "2024-06-18T21:11:49.077Z",
        "dateUpdated": "2024-08-01T21:33:04.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4468 (GCVE-0-2023-4468)

    Vulnerability from nvd – Published: 2023-12-29 09:38 – Updated: 2024-08-02 07:31
    VLAI
    Title
    Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization
    Summary
    A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:31:05.502Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?id.249261"
              },
              {
                "tags": [
                  "signature",
                  "permissions-required",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?ctiid.249261"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902"
              },
              {
                "tags": [
                  "exploit",
                  "x_transferred"
                ],
                "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio 8500",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio 8800",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio C60",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Christoph Wolff"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Pascal Zenker"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Poly Trio 8500, Trio 8800 and Trio C60 ausgemacht. Sie wurde als problematisch eingestuft. Hiervon betroffen ist ein unbekannter Codeblock der Komponente Poly Lens Management Cloud Registration. Dank Manipulation mit unbekannten Daten kann eine missing authorization-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4.6,
                "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-09T16:16:26.423Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.249261"
            },
            {
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.249261"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2023-12-29T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2023-12-29T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-01-09T17:20:44.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2023-4468",
        "datePublished": "2023-12-29T09:38:05.716Z",
        "dateReserved": "2023-08-21T17:04:06.917Z",
        "dateUpdated": "2024-08-02T07:31:05.502Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-9579 (GCVE-0-2024-9579)

    Vulnerability from cvelistv5 – Published: 2024-11-05 16:22 – Updated: 2024-11-05 19:32
    VLAI
    Title
    Certain Poly Video Conference Devices – Potential Remote Code Execution
    Summary
    A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-05 19:13 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    HP, Inc. Certain Poly Video Conference Devices Affected: See HP security bulletin reference for affected versions
    Create a notification for this product.
    poly tc8_firmware Affected: 0 , < 6.3.2 (custom)
        cpe:2.3:o:poly:tc8_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly tc10_firmware Affected: 0 , < 6.3.2 (custom)
        cpe:2.3:o:poly:tc10_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly g7500_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x30_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x50_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x70_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_x52_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_x52_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    poly studio_g62_firmware Affected: 0 , < 4.3.2 (custom)
        cpe:2.3:o:poly:studio_g62_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:poly:tc8_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc8_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "6.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:tc10_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "tc10_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "6.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "g7500_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x30_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x50_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x70_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_x52_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_x52_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:o:poly:studio_g62_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "studio_g62_firmware",
                "vendor": "poly",
                "versions": [
                  {
                    "lessThan": "4.3.2",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-9579",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-05T19:13:45.885761Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-05T19:32:25.537Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Certain Poly Video Conference Devices",
              "vendor": "HP, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "See HP security bulletin reference for affected versions"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.\u003c/span\u003e"
                }
              ],
              "value": "A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "ADJACENT_NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77 Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-05T16:22:01.465Z",
            "orgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
            "shortName": "hp"
          },
          "references": [
            {
              "url": "https://support.hp.com/us-en/document/ish_11536495-11536533-16/hpsbpy03900"
            }
          ],
          "source": {
            "advisory": "HPSBPY03900",
            "discovery": "UNKNOWN"
          },
          "title": "Certain Poly Video Conference Devices \u2013 Potential Remote Code Execution",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "74586083-13ce-40fd-b46a-8e5d23cfbcb2",
        "assignerShortName": "hp",
        "cveId": "CVE-2024-9579",
        "datePublished": "2024-11-05T16:22:01.465Z",
        "dateReserved": "2024-10-07T13:24:15.881Z",
        "dateUpdated": "2024-11-05T19:32:25.537Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6147 (GCVE-0-2024-6147)

    Vulnerability from cvelistv5 – Published: 2024-06-20 20:11 – Updated: 2024-08-01 21:33
    VLAI
    Title
    Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability
    Summary
    Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-06-25 19:21 UTC
    CWE
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    References
    Impacted products
    Vendor Product Version
    Poly Plantronics Hub Affected: 3.24.2 Build 36336
    Create a notification for this product.
    plantronics plantronics_hub Affected: 3.24.2 Build 36336
        cpe:2.3:a:plantronics:plantronics_hub:*:*:*:*:*:windows:*:*
    Create a notification for this product.
    Date Public
    2024-06-18 23:32
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:plantronics:plantronics_hub:*:*:*:*:*:windows:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "plantronics_hub",
                "vendor": "plantronics",
                "versions": [
                  {
                    "status": "affected",
                    "version": "3.24.2 Build 36336"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6147",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-06-25T19:21:00.721267Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-06-26T19:40:03.741Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-01T21:33:04.947Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "name": "ZDI-24-802",
                "tags": [
                  "x_research-advisory",
                  "x_transferred"
                ],
                "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-802/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "Plantronics Hub",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.24.2 Build 36336"
                }
              ]
            }
          ],
          "dateAssigned": "2024-06-18T21:11:49.104Z",
          "datePublic": "2024-06-18T23:32:18.515Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Poly Plantronics Hub. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.\n\nThe specific flaw exists within the Spokes Update Service. By creating a symbolic link, an attacker can abuse the service to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-18271."
            }
          ],
          "metrics": [
            {
              "cvssV3_0": {
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.0"
              },
              "format": "CVSS"
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-06-20T20:11:52.626Z",
            "orgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
            "shortName": "zdi"
          },
          "references": [
            {
              "name": "ZDI-24-802",
              "tags": [
                "x_research-advisory"
              ],
              "url": "https://www.zerodayinitiative.com/advisories/ZDI-24-802/"
            }
          ],
          "source": {
            "lang": "en",
            "value": "Michael DePlante (@izobashi) of Trend Micro\u0027s Zero Day Initiative"
          },
          "title": "Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "99f1926a-a320-47d8-bbb5-42feb611262e",
        "assignerShortName": "zdi",
        "cveId": "CVE-2024-6147",
        "datePublished": "2024-06-20T20:11:52.626Z",
        "dateReserved": "2024-06-18T21:11:49.077Z",
        "dateUpdated": "2024-08-01T21:33:04.947Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2023-4468 (GCVE-0-2023-4468)

    Vulnerability from cvelistv5 – Published: 2023-12-29 09:38 – Updated: 2024-08-02 07:31
    VLAI
    Title
    Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization
    Summary
    A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
    CWE
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T07:31:05.502Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "vdb-entry",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?id.249261"
              },
              {
                "tags": [
                  "signature",
                  "permissions-required",
                  "x_transferred"
                ],
                "url": "https://vuldb.com/?ctiid.249261"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902"
              },
              {
                "tags": [
                  "exploit",
                  "x_transferred"
                ],
                "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices"
              },
              {
                "tags": [
                  "related",
                  "x_transferred"
                ],
                "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio 8500",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio 8800",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            },
            {
              "modules": [
                "Poly Lens Management Cloud Registration"
              ],
              "product": "Trio C60",
              "vendor": "Poly",
              "versions": [
                {
                  "status": "affected",
                  "version": "n/a"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Christoph Wolff"
            },
            {
              "lang": "en",
              "type": "finder",
              "value": "Pascal Zenker"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability."
            },
            {
              "lang": "de",
              "value": "Es wurde eine Schwachstelle in Poly Trio 8500, Trio 8800 and Trio C60 ausgemacht. Sie wurde als problematisch eingestuft. Hiervon betroffen ist ein unbekannter Codeblock der Komponente Poly Lens Management Cloud Registration. Dank Manipulation mit unbekannten Daten kann eine missing authorization-Schwachstelle ausgenutzt werden. Ein Angriff setzt physischen Zugriff auf dem Zielobjekt voraus. Der Exploit steht zur \u00f6ffentlichen Verf\u00fcgung."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.1"
              }
            },
            {
              "cvssV3_0": {
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                "version": "3.0"
              }
            },
            {
              "cvssV2_0": {
                "baseScore": 4.6,
                "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
                "version": "2.0"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-862",
                  "description": "CWE-862 Missing Authorization",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-01-09T16:16:26.423Z",
            "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
            "shortName": "VulDB"
          },
          "references": [
            {
              "tags": [
                "vdb-entry"
              ],
              "url": "https://vuldb.com/?id.249261"
            },
            {
              "tags": [
                "signature",
                "permissions-required"
              ],
              "url": "https://vuldb.com/?ctiid.249261"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://modzero.com/en/advisories/mz-23-01-poly-voip/"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902"
            },
            {
              "tags": [
                "exploit"
              ],
              "url": "https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices"
            },
            {
              "tags": [
                "related"
              ],
              "url": "https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2023-12-29T00:00:00.000Z",
              "value": "Advisory disclosed"
            },
            {
              "lang": "en",
              "time": "2023-12-29T01:00:00.000Z",
              "value": "VulDB entry created"
            },
            {
              "lang": "en",
              "time": "2024-01-09T17:20:44.000Z",
              "value": "VulDB entry last update"
            }
          ],
          "title": "Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
        "assignerShortName": "VulDB",
        "cveId": "CVE-2023-4468",
        "datePublished": "2023-12-29T09:38:05.716Z",
        "dateReserved": "2023-08-21T17:04:06.917Z",
        "dateUpdated": "2024-08-02T07:31:05.502Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }