Path Traversal Vulnerability in Poly Edge E Devices
CVE-2025-0858
5.8MEDIUM
Key Information:
- Vendor
- HP, Inc.
- Status
- Poly Edge E
- Vendor
- CVE Published:
- 5 February 2025
Summary
A vulnerability has been identified in the firmware builds of Poly Edge E devices that allows for path traversal, potentially enabling unauthorized information disclosure. This issue affects all firmware versions up to and including 8.2.1.0820, emphasizing the need for users to review and update their systems to mitigate risks associated with sensitive data exposure.
Affected Version(s)
Poly Edge E See HP security bulletin reference for affected versions
References
CVSS V4
Score:
5.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved