7.6

CVE-2023-4468

Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PolyTrio 8800 Firmware Version-
   PolyTrio 8800 Version-
PolyTrio C60 Version-
   PolyTrio C60 Version-
PolyLens Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.164
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.6 0.9 6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cna@vuldb.com 4.3 0.9 3.4
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
cna@vuldb.com 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-862 Missing Authorization

The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html
Not Applicable
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices
https://modzero.com/en/advisories/mz-23-01-poly-voip/
https://modzero.com/en/blog/multiple-vulnerabilities-in-poly-products/
Third Party Advisory
https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902
https://vuldb.com/?ctiid.249261
Third Party Advisory
Permissions Required
https://vuldb.com/?id.249261
Third Party Advisory