VYPR

Poly Clariti Manager

by Microfocus

CVEs (14)

  • CVE-2024-41912CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.

  • CVE-2024-41913HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

  • CVE-2025-43022HigJul 22, 2025
    risk 0.47cvss 7.2epss 0.00

    A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow a privileged user to execute SQL commands. HP has addressed the issue in the latest software update.

  • CVE-2025-43487MedJul 23, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The firmware flaw does not properly implement access controls. HP has addressed the issue in the latest software update.

  • CVE-2025-43020MedJul 22, 2025
    risk 0.44cvss 6.8epss 0.00

    A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a privileged user to submit arbitrary input. HP has addressed the issue in the latest software update.

  • CVE-2025-43484MedJul 23, 2025
    risk 0.40cvss 6.1epss 0.00

    A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website does not validate or sanitize the user input before rendering it in the response. HP has addressed the issue in the latest software…

  • CVE-2024-41910MedAug 6, 2024
    risk 0.40cvss 6.1epss 0.00

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware contained multiple XSS vulnerabilities in the version of JavaScript used.

  • CVE-2025-43483MedJul 23, 2025
    risk 0.37cvss 5.7epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the retrieval of hardcoded cryptographic keys. HP has addressed the issue in the latest software update.

  • CVE-2025-43021MedJul 22, 2025
    risk 0.37cvss 5.7epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could allow the use and retrieval of the default password. HP has addressed the issue in the latest software update.

  • CVE-2024-41911MedAug 6, 2024
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The flaw does not properly neutralize input during a web page generation.

  • CVE-2025-43489MedJul 23, 2025
    risk 0.34cvss 5.2epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vulnerability could deserialize untrusted data without validation. HP has addressed the issue in the latest software update.

  • CVE-2025-43488MedJul 23, 2025
    risk 0.31cvss 4.8epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could allow a bypass of the application's XSS filter by submitting untrusted characters. HP has addressed the issue in the latest software update.

  • CVE-2025-43486MedJul 23, 2025
    risk 0.31cvss 4.8epss 0.00

    A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The website allows user input to be stored and rendered without proper sanitization. HP has addressed the issue in the latest software update.

  • CVE-2025-43485MedJul 23, 2025
    risk 0.29cvss 4.5epss 0.00

    A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vulnerability could potentially allow a privileged user to retrieve credentials from the log files. HP has addressed the issue in the latest software update.