PT-2023-29274 · Poly · Vvx 601+36

Christoph Wolff

+1

·

Published

2023-12-29

·

Updated

2024-05-17

·

CVE-2023-4462

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX 310, VVX 311, VVX 350, VVX 400, VVX 401, VVX 410, VVX 411, VVX 450, VVX 500, VVX 501, VVX 600 and VVX 601 (affected versions not specified)
Description A vulnerability has been found in the Web Configuration Application component of the affected devices. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of an attack is rather high, and the exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2023-4462

Affected Products

Ccx 350
Ccx 400
Ccx 500
Ccx 505
Ccx 600
Ccx 700
Edge E100
Edge E220
Edge E300
Edge E320
Edge E350
Edge E400
Edge E450
Edge E500
Edge E550
Poly Trio 8300
Trio 8500
Trio 8800
Trio C60
Vvx 101
Vvx 150
Vvx 201
Vvx 250
Vvx 300
Vvx 301
Vvx 310
Vvx 311
Vvx 350
Vvx 400
Vvx 401
Vvx 410
Vvx 411
Vvx 450
Vvx 500
Vvx 501
Vvx 600
Vvx 601