MEDIUM · 4.9

CVE-2025-14432

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to...

Vulnerability Description

In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to users with admin credentials. This is limited to Microsoft TAC and does not affect configuration changes made using the provisioning server or the device WebUI.

CVSS Score

4.9

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
HpPoly Videoos< 4.6.1-444242
HpPoly Eagleeye Cube-
HpPoly Eagleeye Iv-
HpPoly Studio A2-
HpPoly Studio E60-
HpPoly Studio E70-
HpPoly Studio G62-
HpPoly Studio G7500-
HpPoly Studio Usb-
HpPoly Studio X30-
HpPoly Studio X32-
HpPoly Studio X50-
HpPoly Studio X52-
HpPoly Studio X70-
HpPoly Studio X72-
HpPoly Tcos< 6.6.1-7001859
HpPoly Tc10-
HpPoly Tc8-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-14432?

CVE-2025-14432 is a vulnerability with a CVSS score of 4.9 (MEDIUM). In limited scenarios, sensitive data might be written to the log file if an admin uses Microsoft Teams Admin Center (TAC) to make device configuration changes. The affected log file is visible only to...

How severe is CVE-2025-14432?

CVE-2025-14432 has been rated MEDIUM with a CVSS base score of 4.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-14432?

Check the references section above for vendor advisories and patch information. Affected products include: Hp Poly Videoos, Hp Poly Eagleeye Cube, Hp Poly Eagleeye Iv, Hp Poly Studio A2, Hp Poly Studio E60.