Vulnerability Description
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Polycom | Unified Communications Software | <= 5.8.0 |
| Polycom | Better Together Over Ethernet Connector | <= 3.8.0 |
Related Weaknesses (CWE)
References
- https://support.polycom.com/content/dam/polycom-support/global/documentation/harVendor Advisory
- https://support.polycom.com/content/dam/polycom-support/global/documentation/harVendor Advisory
FAQ
What is CVE-2019-10688?
CVE-2019-10688 is a vulnerability with a CVSS score of 6.8 (MEDIUM). VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between...
How severe is CVE-2019-10688?
CVE-2019-10688 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10688?
Check the references section above for vendor advisories and patch information. Affected products include: Polycom Unified Communications Software, Polycom Better Together Over Ethernet Connector.