PT-2021-8828 · Poly · Poly Trio 8800

Unkl4B

·

Published

2021-12-28

·

Updated

2022-01-10

·

CVE-2018-17875

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Poly Trio 8800 version 5.7.1.4145
Description A remote code execution issue in the ping command allows remote authenticated users to execute commands via unspecified vectors.
Recommendations For Poly Trio 8800 version 5.7.1.4145, consider disabling the ping command as a temporary workaround until a patch is available. Restrict access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-17875

Affected Products

Poly Trio 8800