PT-2023-29276 · Poly · Poly Ccx 400+3

Christoph Wolff

+1

·

Published

2023-12-29

·

Updated

2024-05-17

·

CVE-2023-4466

CVSS v2.0

3.3

Low

VectorAV:N/AC:L/Au:M/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Poly CCX 400 (affected versions not specified) Poly CCX 600 (affected versions not specified) Poly Trio 8800 (affected versions not specified) Poly Trio C60 (affected versions not specified)
Description A vulnerability has been found in the Web Interface component, leading to protection mechanism failure. The attack can be launched remotely. The vendor does not regard this as a vulnerability, considering it a feature for customers with various environmental needs met through different firmware builds. To avoid potential roll-back attacks, the vendor removes vulnerable builds from public servers as a remediation effort. The exploit has been disclosed to the public and may be used.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

CVE-2023-4466

Affected Products

Poly Ccx 400
Poly Ccx 600
Poly Trio 8800
Poly Trio C60