Vulnerability Description
A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Poly | Trio 8800 Firmware | 5.4.0.12197 |
| Poly | Trio 8800 | - |
References
- http://unkl4b.github.io/Authenticated-RCE-in-Polycom-Trio-8800-pt-1/ExploitThird Party Advisory
- https://support.polycom.com/content/support/emea/emea/en/support/voice/polycom-tProductThird Party Advisory
- http://unkl4b.github.io/Authenticated-RCE-in-Polycom-Trio-8800-pt-1/ExploitThird Party Advisory
- https://support.polycom.com/content/support/emea/emea/en/support/voice/polycom-tProductThird Party Advisory
FAQ
What is CVE-2018-17875?
CVE-2018-17875 is a vulnerability with a CVSS score of 8.8 (HIGH). A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.
How severe is CVE-2018-17875?
CVE-2018-17875 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-17875?
Check the references section above for vendor advisories and patch information. Affected products include: Poly Trio 8800 Firmware, Poly Trio 8800.