Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5wpv-2g59-v5gg

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.3

Описание

An RCE (Remote Code Execution) vulnerability exists in the UCS software through 6.0.0 used by Polycom Products. The vulnerability could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system and uploading an arbitrary file.

An RCE (Remote Code Execution) vulnerability exists in the UCS software through 6.0.0 used by Polycom Products. The vulnerability could allow an authenticated, remote attacker to execute arbitrary code. The vulnerability is due to improper validation of files uploaded to the affected application. An attacker could exploit this vulnerability by authenticating to the affected system and uploading an arbitrary file.

EPSS

Процентиль: 79%
0.01194
Низкий

8.3 High

CVSS3

Дефекты

CWE-749

Связанные уязвимости

CVSS3: 8.3
nvd
больше 6 лет назад

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

EPSS

Процентиль: 79%
0.01194
Низкий

8.3 High

CVSS3

Дефекты

CWE-749