CVE Tools

Poly

10 CVEs tracked since 2022. Since Jul 2022, none of them reached CISA KEV.

Poly CVEs per month

Jul 2022 to Dec 2023. Point at a month, or focus the strip and use the arrow keys.
Poly CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2022-0730
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-12null or fewer
2023-01null or fewer
2023-02null or fewer
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-08null or fewer
2023-09null or fewer
2023-10null or fewer
2023-11null or fewer
2023-1270

Products

The products that kept showing up in Poly's monthly top three, with their CVEs summed over those months.

  1. Trio 880071 month
  2. Trio 8800 Firmware71 month
  3. Trio C6061 month
  4. Eagleeye Director Ii Firmware21 month
  5. Studio X50 Firmware11 month
  6. Studio X70 Firmware11 month

Latest CVEs

The 14 most recently published vulnerabilities affecting Poly.

  1. CVE-2024-6147Poly Plantronics Hub Link Following Local Privilege Escalation Vulnerability7.8
  2. CVE-2023-4468Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization4.3
  3. CVE-2023-4467Poly Trio 8800 Test Automation Mode backdoor6.2
  4. CVE-2023-4466Poly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanism2.7
  5. CVE-2023-4465Poly VVX 601 Configuration File Import unverified password change2.7
  6. CVE-2023-4464Poly VVX 601 Diagnostic Telnet Mode os command injection7.2
  7. CVE-2023-4463Poly CCX 400/CCX 600/Trio 8800/Trio C60 HTTP Header denial of service5.3
  8. CVE-2023-4462Poly VVX 601 Web Configuration Application random values3.7
  9. CVE-2023-24282An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.5.4
  10. CVE-2022-26481An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.8.8
  11. CVE-2022-26482An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin.7.2
  12. CVE-2022-26479An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authen...9.8
  13. CVE-2018-17875A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.8.8
  14. CVE-2021-37145A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capabi...7.2

The record

Peak rank
#98 in Dec 2023
Busiest month shown
Dec 2023, 7 CVEs
Months with a KEV entry
0 since Jul 2022
Monthly snapshots
2 since 2022
Poly's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store