VYPR
Vendor

Polycom

Products
73
CVEs
63
Across products
124
Status
Private

Products

73
View all 73 products →

Recent CVEs

63
View all 63 CVEs →
  • CVE-2015-4683CriSep 19, 2017
    risk 0.67cvss 9.8epss 0.07

    Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows attackers to obtain sensitive information and potentially gain privileges by leveraging use of session identifiers as parameters with HTTP GET requests.

  • CVE-2024-41912CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly implement access controls.

  • CVE-2022-26479CriJul 17, 2022
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

  • CVE-2012-6611CriFeb 10, 2020
    risk 0.64cvss 9.8epss 0.03

    An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without setting this password.

  • CVE-2018-15128CriMay 13, 2019
    risk 0.64cvss 9.8epss 0.05

    An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functionality because of a Buffer Overflow via crafted packets.

  • CVE-2012-6610HigJan 28, 2020
    risk 0.61cvss 8.8epss 0.11

    Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.

  • CVE-2024-41913HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability was discovered in the firmware builds up to 10.10.2.2 in Poly Clariti Manager devices. The firmware flaw does not properly sanitize User input.

  • CVE-2022-26481HigJul 17, 2022
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.

  • CVE-2018-17875HigDec 28, 2021
    risk 0.57cvss 8.8epss 0.03

    A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.

  • CVE-2021-41322HigOct 4, 2021
    risk 0.57cvss 8.8epss 0.02

    Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.

  • CVE-2018-7565HigMar 7, 2018
    risk 0.57cvss 8.8epss 0.00

    CSRF exists on Polycom QDX 6000 devices.

  • CVE-2017-12857HigAug 25, 2017
    risk 0.57cvss 8.8epss 0.02

    Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a…

  • CVE-2019-12948HigJul 29, 2019
    risk 0.54cvss 8.3epss 0.02

    A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or…

  • CVE-2015-4681HigSep 19, 2017
    risk 0.54cvss 7.8epss 0.02

    Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allows local users to have unspecified impact via vectors related to weak passwords.

  • CVE-2025-34093HigJul 10, 2025
    risk 0.52cvss epss 0.02

    An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible over Telnet. The lan traceroute command in the devcmds console accepts unsanitized input, allowing attackers to execute arbitrary system commands. By injecting…

  • CVE-2019-14259HigAug 1, 2019
    risk 0.52cvss 8.0epss 0.03

    On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands…

  • CVE-2015-8300HigAug 28, 2017
    risk 0.51cvss 7.8epss 0.01

    Polycom BToE Connector before 3.0.0 uses weak permissions (Everyone: Full Control) for "Program Files (x86)\polycom\polycom btoe connector\plcmbtoesrv.exe," which allows local users to gain privileges via a Trojan horse file.

  • CVE-2025-22918HigFeb 3, 2025
    risk 0.49cvss 7.5epss 0.00

    Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

  • CVE-2022-26482HigJul 17, 2022
    risk 0.49cvss 7.2epss 0.23

    An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.

  • CVE-2012-6609HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.02

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.