CVE-2018-14935: XSS
Published Nov 15, 2018
·Updated
The Web administration console on Polycom Trio devices with software before 5.5.4 has XSS.
Affected Software
2 affected components
Polycom Trio 8500 Firmware<5.5.4
Polycom Trio 8500
Event History
Nov 15, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-14935?
CVE-2018-14935 is classified as a medium severity vulnerability due to cross-site scripting (XSS) in the Web administration console.
2
How do I fix CVE-2018-14935?
To mitigate CVE-2018-14935, update the Polycom Trio devices to firmware version 5.5.4 or later.
3
Which devices are affected by CVE-2018-14935?
CVE-2018-14935 affects Polycom Trio 8500 devices running firmware before version 5.5.4.
4
What type of vulnerability is CVE-2018-14935?
CVE-2018-14935 is a cross-site scripting (XSS) vulnerability that allows attackers to execute malicious scripts in a user's browser.
5
Is any action required for devices not running vulnerable firmware related to CVE-2018-14935?
Devices running Polycom Trio firmware version 5.5.4 or higher are not affected by CVE-2018-14935 and therefore do not require any action.