Credential Retrieval Vulnerability in Poly Clariti Manager by HP
CVE-2025-43485

5.7MEDIUM

Key Information:

Vendor

HP

Vendor
CVE Published:
23 July 2025

What is CVE-2025-43485?

A security vulnerability has been identified in Poly Clariti Manager for versions prior to 10.12.2, which may allow a privileged user to access sensitive credentials stored in log files. This poses a risk to the confidentiality of user data. HP has released an update to mitigate this vulnerability, and users are strongly encouraged to upgrade to version 10.12.2 or later.

Affected Version(s)

Poly Clariti Manager See HP Security Bulletin reference for affected versions.

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

.