Vulnerability Description
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Poly | Trio 8800 Firmware | 7.2.2.1094 |
| Poly | Trio 8800 | - |
Related Weaknesses (CWE)
References
- http://polycom.comProduct
- https://www.cryptnetix.com/blog/2023/01/19/Polycom-Trio-Vulnerability-DisclosureExploitThird Party Advisory
- http://polycom.comProduct
- https://www.cryptnetix.com/blog/2023/01/19/Polycom-Trio-Vulnerability-DisclosureExploitThird Party Advisory
FAQ
What is CVE-2023-24282?
CVE-2023-24282 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
How severe is CVE-2023-24282?
CVE-2023-24282 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-24282?
Check the references section above for vendor advisories and patch information. Affected products include: Poly Trio 8800 Firmware, Poly Trio 8800.