CVEs (6)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Polycom 2Unified Communications Software United Communications SoftwareNov 21, 2024 Jul 29, 2019 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin...Show more |
1Polycom 2Better Together Over Ethernet Connector Unified Communications SoftwareNov 21, 2024 Jun 24, 2019 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and th...Show more |
1Polycom 2Better Together Over Ethernet Connector Unified Communications SoftwareNov 21, 2024 Apr 23, 2019 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host applicatio...Show more |
1Polycom 3Unified Communications Software Vvx 500 FirmwareVvx 601 FirmwareNov 21, 2024 Oct 24, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise inst...Show more |
1Polycom 3Unified Communications Software Vvx 500 FirmwareVvx 601 FirmwareNov 21, 2024 Oct 24, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Busin...Show more |
1Polycom 1Unified Communications Software May 13, 2026 Aug 25, 2017 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability c...Show more |