PT-2021-21528 · Poly · Poly Cx5100+1

Published

2021-09-07

·

Updated

2024-08-04

·

CVE-2021-37145

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poly CX5500 and CX5100 version 1.3.5
Description A command-injection vulnerability in an authenticated Telnet connection leads to Privilege Escalation and Remote Code Execution capability. This issue only affects products that are no longer supported by the maintainer.
Recommendations For Poly CX5500 and CX5100 version 1.3.5, as the products are no longer supported, consider replacing them with supported versions or alternatives to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-37145

Affected Products

Poly Cx5100
Poly Cx5500