CVE-2017-12857: Infoleak
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could contain an administrator's password or other sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12857?
CVE-2017-12857 has been assigned a moderate severity level due to its potential for information disclosure.
How do I fix CVE-2017-12857?
To mitigate CVE-2017-12857, upgrade your Polycom devices to UCS version 4.0.12 or later, or to version 5.4.5 rev AG or later.
What devices are affected by CVE-2017-12857?
CVE-2017-12857 affects Polycom SoundStation IP, VVX, and RealPresence Trio devices running older software versions.
What type of attack does CVE-2017-12857 allow?
CVE-2017-12857 allows an authenticated remote attacker to read a segment of the phone's memory.
Is it safe to use older versions of Polycom software after CVE-2017-12857?
Using older versions of Polycom software is not safe as they are vulnerable to CVE-2017-12857.