PT-2019-11994 · Polycom · Polycom Vvx+1
Published
2019-04-23
·
Updated
2019-06-17
·
CVE-2019-10688
CVSS v3.1
6.8
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Polycom VVX products versions prior to UCS 5.9.2
Description
The issue concerns the use of hard-coded credentials to establish connections between the host application and the device in VVX products. This specifically affects versions including and prior to UCS 5.9.2 with the Better Together over Ethernet Connector (BToE) application 3.9.1.
Recommendations
For versions prior to UCS 5.9.2, update to a version that does not use hard-coded credentials for establishing connections.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Better Together Over Ethernet Connector
Polycom Vvx