Path Traversal Vulnerability in Poly Edge E Devices
CVE-2025-0858

5.8MEDIUM

Key Information:

Vendor
HP, Inc.
Status
Poly Edge E
Vendor
CVE Published:
5 February 2025

Summary

A vulnerability has been identified in the firmware builds of Poly Edge E devices that allows for path traversal, potentially enabling unauthorized information disclosure. This issue affects all firmware versions up to and including 8.2.1.0820, emphasizing the need for users to review and update their systems to mitigate risks associated with sensitive data exposure.

Affected Version(s)

Poly Edge E See HP security bulletin reference for affected versions

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.