Lucene search

K
cve[email protected]CVE-2019-12948
HistoryJul 29, 2019 - 4:15 p.m.

CVE-2019-12948

2019-07-2916:15:12
CWE-749
web.nvd.nist.gov
24
cve-2019-12948
vulnerability
web-based management
polycom
dos
authenticated
remote attacker
admin privileges
arbitrary code

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.7%

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

Affected configurations

NVD
Node
polycomunified_communications_softwareRange<5.8.5.1256
OR
polycomunified_communications_softwareRange5.9.35.9.3.2857
OR
polycomunified_communications_softwareRange6.0.06.0.0.4839
AND
polycomc12Match-
OR
polycomc16Match-
OR
polycomc8Match-
OR
polycomvvx150Match-
OR
polycomvvx201Match-
OR
polycomvvx250Match-
OR
polycomvvx301Match-
OR
polycomvvx311Match-
OR
polycomvvx350Match-
OR
polycomvvx401Match-
OR
polycomvvx411Match-
OR
polycomvvx450Match-
OR
polycomvvx501Match-
OR
polycomvvx601Match-
Node
polycomunited_communications_softwareRange<5.9.0
AND
polycomtrio_8500Match-
OR
polycomtrio_8800Match-
Node
polycomunited_communications_softwareRange<4.0.14.1580
AND
polycomsoundpoint_ip_300Match-
OR
polycomsoundpoint_ip_301Match-
OR
polycomsoundpoint_ip_320Match-
OR
polycomsoundpoint_ip_321Match-
OR
polycomsoundpoint_ip_330Match-
OR
polycomsoundpoint_ip_331Match-
OR
polycomsoundpoint_ip_335Match-
OR
polycomsoundpoint_ip_430Match-
OR
polycomsoundpoint_ip_450Match-
OR
polycomsoundpoint_ip_500Match-
OR
polycomsoundpoint_ip_501Match-
OR
polycomsoundpoint_ip_550Match-
OR
polycomsoundpoint_ip_560Match-
OR
polycomsoundpoint_ip_600Match-
OR
polycomsoundpoint_ip_601Match-
OR
polycomsoundpoint_ip_650Match-
OR
polycomsoundpoint_ip_670Match-
OR
polycomsoundpoint_pro_se-220Match-
OR
polycomsoundpoint_pro_se-225Match-
OR
polycomsoundstation_duoMatch-
OR
polycomsoundstation_ip_4000Match-
OR
polycomsoundstation_ip_5000Match-
OR
polycomsoundstation_ip_6000Match-
OR
polycomsoundstation_ip_7000Match-
OR
polycomsoundstation_ip_7000_video_integrationMatch-
OR
polycomsoundstation_vtx_1000Match-
OR
polycomsoundstation2Match-
OR
polycomsoundstation2_avaya_2490Match-
OR
polycomsoundstation2_direct_connect_for_nortelMatch-
OR
polycomsoundstation2wMatch-
Node
polycomunified_communications_softwareRange<5.8.5.1256
OR
polycomunified_communications_softwareRange5.9.35.9.3.2857
AND
polycomvvx300Match-
OR
polycomvvx310Match-
OR
polycomvvx400Match-
OR
polycomvvx410Match-
OR
polycomvvx500Match-
OR
polycomvvx600Match-

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

8.3 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

8.3 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.7%

Related for CVE-2019-12948