Vulnerability Description
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Poly | Studio X30 Firmware | < 3.7.0 |
| Poly | Studio X30 | - |
| Poly | Studio X70 Firmware | < 3.7.0 |
| Poly | Studio X70 | - |
| Poly | G7500 Firmware | < 3.7.0 |
| Poly | G7500 | - |
| Poly | Studio X50 Firmware | < 3.7.0 |
| Poly | Studio X50 | - |
Related Weaknesses (CWE)
References
- https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injectiExploitThird Party Advisory
- https://www.poly.com/us/en/support/security-centerVendor Advisory
- https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injectiExploitThird Party Advisory
- https://www.poly.com/us/en/support/security-centerVendor Advisory
FAQ
What is CVE-2022-26481?
CVE-2022-26481 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
How severe is CVE-2022-26481?
CVE-2022-26481 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-26481?
Check the references section above for vendor advisories and patch information. Affected products include: Poly Studio X30 Firmware, Poly Studio X30, Poly Studio X70 Firmware, Poly Studio X70, Poly G7500 Firmware.