PT-2023-29276 · Poly · Poly Ccx 400+3
Christoph Wolff
+1
·
Published
2023-12-29
·
Updated
2024-05-17
·
CVE-2023-4466
CVSS v2.0
3.3
Low
| Vector | AV:N/AC:L/Au:M/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Poly CCX 400 (affected versions not specified)
Poly CCX 600 (affected versions not specified)
Poly Trio 8800 (affected versions not specified)
Poly Trio C60 (affected versions not specified)
Description
A vulnerability has been found in the Web Interface component, leading to protection mechanism failure. The attack can be launched remotely. The vendor does not regard this as a vulnerability, considering it a feature for customers with various environmental needs met through different firmware builds. To avoid potential roll-back attacks, the vendor removes vulnerable builds from public servers as a remediation effort. The exploit has been disclosed to the public and may be used.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Poly Ccx 400
Poly Ccx 600
Poly Trio 8800
Poly Trio C60