PT-2023-8292 · Poly · Poly Edge E550+36

Christoph Wolff

+1

·

Published

2023-12-29

·

Updated

2024-05-17

·

CVE-2023-4464

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Poly Trio 8300 versions prior to the fixed version Poly Trio 8500 versions prior to the fixed version Poly Trio 8800 versions prior to the fixed version Poly Trio C60 versions prior to the fixed version Poly CCX 350 versions prior to the fixed version Poly CCX 400 versions prior to the fixed version Poly CCX 500 versions prior to the fixed version Poly CCX 505 versions prior to the fixed version Poly CCX 600 versions prior to the fixed version Poly CCX 700 versions prior to the fixed version Poly EDGE E100 versions prior to the fixed version Poly EDGE E220 versions prior to the fixed version Poly EDGE E300 versions prior to the fixed version Poly EDGE E320 versions prior to the fixed version Poly EDGE E350 versions prior to the fixed version Poly EDGE E400 versions prior to the fixed version Poly EDGE E450 versions prior to the fixed version Poly EDGE E500 versions prior to the fixed version Poly EDGE E550 versions prior to the fixed version Poly VVX 101 versions prior to the fixed version Poly VVX 150 versions prior to the fixed version Poly VVX 201 versions prior to the fixed version Poly VVX 250 versions prior to the fixed version Poly VVX 300 versions prior to the fixed version Poly VVX 301 versions prior to the fixed version Poly VVX 310 versions prior to the fixed version Poly VVX 311 versions prior to the fixed version Poly VVX 350 versions prior to the fixed version Poly VVX 400 versions prior to the fixed version Poly VVX 401 versions prior to the fixed version Poly VVX 410 versions prior to the fixed version Poly VVX 411 versions prior to the fixed version Poly VVX 450 versions prior to the fixed version Poly VVX 500 versions prior to the fixed version Poly VVX 501 versions prior to the fixed version Poly VVX 600 versions prior to the fixed version Poly VVX 601 versions prior to the fixed version
Description The issue affects some unknown processing of the component Diagnostic Telnet Mode, leading to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations To resolve the issue for each affected version, it is recommended to upgrade the affected component. As a temporary workaround, consider disabling the Diagnostic Telnet Mode until a patch is available. Restrict access to the Diagnostic Telnet Mode to minimize the risk of exploitation. Avoid using the Diagnostic Telnet Mode in the affected devices until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-00375
CVE-2023-4464

Affected Products

Poly Ccx 350
Poly Ccx 400
Poly Ccx 500
Poly Ccx 505
Poly Ccx 600
Poly Ccx 700
Poly Edge E100
Poly Edge E220
Poly Edge E300
Poly Edge E320
Poly Edge E350
Poly Edge E400
Poly Edge E450
Poly Edge E500
Poly Edge E550
Poly Trio 8300
Poly Trio 8500
Poly Trio 8800
Poly Trio C60
Poly Vvx 101
Poly Vvx 150
Poly Vvx 201
Poly Vvx 250
Poly Vvx 300
Poly Vvx 301
Poly Vvx 310
Poly Vvx 311
Poly Vvx 350
Poly Vvx 400
Poly Vvx 401
Poly Vvx 410
Poly Vvx 411
Poly Vvx 450
Poly Vvx 500
Poly Vvx 501
Poly Vvx 600
Poly Vvx 601