PT-2018-12809 · Polycom · Polycom Trio

Published

2018-11-15

·

Updated

2019-10-03

·

CVE-2018-14934

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Polycom Trio devices versions prior to 5.5.4
Description The issue concerns the Bluetooth subsystem, which has incorrect access control. This allows an attacker to connect to the device without authentication and record audio from the device microphone.
Recommendations For versions prior to 5.5.4, update to version 5.5.4 or later to resolve the issue.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14934

Affected Products

Polycom Trio