8.3

CVE-2019-12948

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PolycomUnified Communications Software Version < 5.8.5.1256
   PolycomC12 Version-
   PolycomC16 Version-
   PolycomC8 Version-
   PolycomVvx150 Version-
   PolycomVvx201 Version-
   PolycomVvx250 Version-
   PolycomVvx301 Version-
   PolycomVvx311 Version-
   PolycomVvx350 Version-
   PolycomVvx401 Version-
   PolycomVvx411 Version-
   PolycomVvx450 Version-
   PolycomVvx501 Version-
   PolycomVvx601 Version-
PolycomUnified Communications Software Version >= 5.9.3 < 5.9.3.2857
   PolycomC12 Version-
   PolycomC16 Version-
   PolycomC8 Version-
   PolycomVvx150 Version-
   PolycomVvx201 Version-
   PolycomVvx250 Version-
   PolycomVvx301 Version-
   PolycomVvx311 Version-
   PolycomVvx350 Version-
   PolycomVvx401 Version-
   PolycomVvx411 Version-
   PolycomVvx450 Version-
   PolycomVvx501 Version-
   PolycomVvx601 Version-
PolycomUnified Communications Software Version >= 6.0.0 < 6.0.0.4839
   PolycomC12 Version-
   PolycomC16 Version-
   PolycomC8 Version-
   PolycomVvx150 Version-
   PolycomVvx201 Version-
   PolycomVvx250 Version-
   PolycomVvx301 Version-
   PolycomVvx311 Version-
   PolycomVvx350 Version-
   PolycomVvx401 Version-
   PolycomVvx411 Version-
   PolycomVvx450 Version-
   PolycomVvx501 Version-
   PolycomVvx601 Version-
PolycomUnited Communications Software Version < 5.9.0
   PolycomTrio 8500 Version-
   PolycomTrio 8800 Version-
PolycomUnited Communications Software Version < 4.0.14.1580
   PolycomSoundpoint Ip 300 Version-
   PolycomSoundpoint Ip 301 Version-
   PolycomSoundpoint Ip 320 Version-
   PolycomSoundpoint Ip 321 Version-
   PolycomSoundpoint Ip 330 Version-
   PolycomSoundpoint Ip 331 Version-
   PolycomSoundpoint Ip 335 Version-
   PolycomSoundpoint Ip 430 Version-
   PolycomSoundpoint Ip 450 Version-
   PolycomSoundpoint Ip 500 Version-
   PolycomSoundpoint Ip 501 Version-
   PolycomSoundpoint Ip 550 Version-
   PolycomSoundpoint Ip 560 Version-
   PolycomSoundpoint Ip 600 Version-
   PolycomSoundpoint Ip 601 Version-
   PolycomSoundpoint Ip 650 Version-
   PolycomSoundpoint Ip 670 Version-
   PolycomSoundpoint Pro Se-220 Version-
   PolycomSoundpoint Pro Se-225 Version-
   PolycomSoundstation Duo Version-
   PolycomSoundstation Ip 4000 Version-
   PolycomSoundstation Ip 5000 Version-
   PolycomSoundstation Ip 6000 Version-
   PolycomSoundstation Ip 7000 Version-
   PolycomSoundstation Ip 7000 Video Integration Version-
   PolycomSoundstation Vtx 1000 Version-
   PolycomSoundstation2 Version-
   PolycomSoundstation2 Avaya 2490 Version-
   PolycomSoundstation2 Direct Connect For Nortel Version-
   PolycomSoundstation2w Version-
PolycomUnified Communications Software Version < 5.8.5.1256
   PolycomVvx300 Version-
   PolycomVvx310 Version-
   PolycomVvx400 Version-
   PolycomVvx410 Version-
   PolycomVvx500 Version-
   PolycomVvx600 Version-
PolycomUnified Communications Software Version >= 5.9.3 < 5.9.3.2857
   PolycomVvx300 Version-
   PolycomVvx310 Version-
   PolycomVvx400 Version-
   PolycomVvx410 Version-
   PolycomVvx500 Version-
   PolycomVvx600 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.783
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.3 2.8 5.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-749 Exposed Dangerous Method or Function

The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.