LOW · 2.7

CVE-2023-4466

A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface...

Vulnerability Description

A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249259.

CVSS Score

2.7

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
PolyCcx 400 Firmware-
PolyCcx 400-
PolyCcx 600 Firmware-
PolyCcx 600-
PolyTrio 8800 Firmware-
PolyTrio 8800-
PolyTrio C60 Firmware-
PolyTrio C60-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-4466?

CVE-2023-4466 is a vulnerability with a CVSS score of 2.7 (LOW). A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface...

How severe is CVE-2023-4466?

CVE-2023-4466 has been rated LOW with a CVSS base score of 2.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-4466?

Check the references section above for vendor advisories and patch information. Affected products include: Poly Ccx 400 Firmware, Poly Ccx 400, Poly Ccx 600 Firmware, Poly Ccx 600, Poly Trio 8800 Firmware.