Poly
10 CVEs tracked since 2022. Since Jul 2022, none of them reached CISA KEV.
Poly CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-07 | 3 | 0 |
| 2022-08 | null or fewer | |
| 2022-09 | null or fewer | |
| 2022-10 | null or fewer | |
| 2022-11 | null or fewer | |
| 2022-12 | null or fewer | |
| 2023-01 | null or fewer | |
| 2023-02 | null or fewer | |
| 2023-03 | null or fewer | |
| 2023-04 | null or fewer | |
| 2023-05 | null or fewer | |
| 2023-06 | null or fewer | |
| 2023-07 | null or fewer | |
| 2023-08 | null or fewer | |
| 2023-09 | null or fewer | |
| 2023-10 | null or fewer | |
| 2023-11 | null or fewer | |
| 2023-12 | 7 | 0 |
Products
The products that kept showing up in Poly's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 14 most recently published vulnerabilities affecting Poly.
- CVE-2024-6147Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability7.8
- CVE-2023-4468Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization4.3
- CVE-2023-4467Poly Trio 8800 Test Automation Mode backdoor6.2
- CVE-2023-4466Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanism2.7
- CVE-2023-4465Poly VVX 601 Configuration File Import unverified password change2.7
- CVE-2023-4464Poly VVX 601 Diagnostic Telnet Mode os command injection7.2
- CVE-2023-4463Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of service5.3
- CVE-2023-4462Poly VVX 601 Web Configuration Application random values3.7
- CVE-2023-24282An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.5.4
- CVE-2022-26481An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.8.8
- CVE-2022-26482An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.7.2
- CVE-2022-26479An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authen...9.8
- CVE-2018-17875A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.8.8
- CVE-2021-37145A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capabi...7.2
The record
- Peak rank
- #98 in Dec 2023
- Busiest month shown
- Dec 2023, 7 CVEs
- Months with a KEV entry
- 0 since Jul 2022
- Monthly snapshots
- 2 since 2022