Cross-Site Scripting Vulnerability in Polycom Trio Devices
CVE-2018-14935

6.1MEDIUM

Key Information:

Vendor

Polycom

Vendor
CVE Published:
15 November 2018

What is CVE-2018-14935?

An XSS vulnerability has been identified in the web administration console of Polycom Trio devices running software versions earlier than 5.5.4. This issue allows attackers to inject malicious scripts into web pages viewed by other users, potentially compromising the communication and data integrity of affected systems. It is crucial for administrators to upgrade their devices to the latest software version to mitigate these risks and ensure the security of their networks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.