CVE-2018-10946: Infoleak
Published Jun 13, 2019
·Updated
An issue was discovered in versions earlier than 1.3.0-66872 for Polycom RealPresence Debut that allows attackers to arbitrarily read the admin user's password via the admin web UI.
Affected Software
2 affected components
Polycom Realpresence Debut Firmware<1.3.0-66872
Polycom RealPresence Debut
Event History
Jun 13, 2019
CVE Published
via MITRE·06:06 PM
Data Sourced
via MITRE·06:06 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10946?
CVE-2018-10946 has a medium severity level due to potential unauthorized access to admin credentials.
2
How do I fix CVE-2018-10946?
To fix CVE-2018-10946, upgrade Polycom RealPresence Debut firmware to version 1.3.0-66872 or later.
3
Which versions of Polycom RealPresence Debut are affected by CVE-2018-10946?
CVE-2018-10946 affects versions of Polycom RealPresence Debut earlier than 1.3.0-66872.
4
What type of attack does CVE-2018-10946 enable?
CVE-2018-10946 allows attackers to arbitrarily read the admin user's password through the admin web UI.
5
What impact does CVE-2018-10946 have on security?
CVE-2018-10946 can lead to unauthorized access to the Polycom RealPresence Debut administration interface, compromising device security.