PT-2023-8254 · Poly · Vvx 601+36
Christoph Wolff
+1
·
Published
2023-12-29
·
Updated
2024-05-17
·
CVE-2023-4465
CVSS v2.0
6.1
Medium
| Vector | AV:N/AC:L/Au:M/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX 310, VVX 311, VVX 350, VVX 400, VVX 401, VVX 410, VVX 411, VVX 450, VVX 500, VVX 501, VVX 600, and VVX 601
Description
The issue is related to a lack of necessary checks when changing the password, allowing a remote attacker to change the administrator's password. The manipulation of the
device.auth.localAdminPassword argument leads to an unverified password change. It is possible to launch the attack remotely.Recommendations
For Poly Trio 8300, Trio 8500, Trio 8800, Trio C60, CCX 350, CCX 400, CCX 500, CCX 505, CCX 600, CCX 700, EDGE E100, EDGE E220, EDGE E300, EDGE E320, EDGE E350, EDGE E400, EDGE E450, EDGE E500, EDGE E550, VVX 101, VVX 150, VVX 201, VVX 250, VVX 300, VVX 301, VVX 310, VVX 311, VVX 350, VVX 400, VVX 401, VVX 410, VVX 411, VVX 450, VVX 500, VVX 501, VVX 600, and VVX 601:
As a temporary workaround, consider disabling the Configuration File Import component until a patch is available.
Restrict access to the
device.auth.localAdminPassword argument to minimize the risk of exploitation.
Avoid using the device.auth.localAdminPassword argument in the affected configuration file import until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ccx 350
Ccx 400
Ccx 500
Ccx 505
Ccx 600
Ccx 700
Edge E100
Edge E220
Edge E300
Edge E320
Edge E350
Edge E400
Edge E450
Edge E500
Edge E550
Poly Trio 8300
Trio 8500
Trio 8800
Trio C60
Vvx 101
Vvx 150
Vvx 201
Vvx 250
Vvx 300
Vvx 301
Vvx 310
Vvx 311
Vvx 350
Vvx 400
Vvx 401
Vvx 410
Vvx 411
Vvx 450
Vvx 500
Vvx 501
Vvx 600
Vvx 601