Hard-Coded Credential Vulnerability in Polycom VVX Products
CVE-2019-10688

6.8MEDIUM

What is CVE-2019-10688?

Polycom's VVX products, specifically those utilizing software versions including and preceding UCS 5.9.2 and the Better Together over Ethernet (BToE) application version 3.9.1, are susceptible to a serious security flaw. This vulnerability stems from the use of hard-coded credentials that enable connections between the host application and the devices, thereby compromising the security of the entire system. Organizations using affected versions may face unauthorized access and potential exploitation of their networks unless appropriate action is taken.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.