CVE-2018-17875: High severity poly firmware vulnerability
Published Dec 28, 2021
·Updated
A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors.
Affected Software
22 affected components
Poly Trio 8800 Firmware=5.4.0.12197
Poly Trio 8800 Firmware=5.4.0.12541
Poly Trio 8800 Firmware=5.4.0.12856
Poly Trio 8800 Firmware=5.4.1.17597
Poly Trio 8800 Firmware=5.4.2.5400
Poly Trio 8800 Firmware=5.4.3.2007
Poly Trio 8800 Firmware=5.4.3.2389
Poly Trio 8800 Firmware=5.4.3.2400
Poly Trio 8800 Firmware=5.4.4.7511
Poly Trio 8800 Firmware=5.4.4.7609
Poly Trio 8800 Firmware=5.4.4.7776
Poly Trio 8800 Firmware=5.4.5.9111
Poly Trio 8800 Firmware=5.4.5.9658
Poly Trio 8800 Firmware=5.5.2.11338
Poly Trio 8800 Firmware=5.5.2.11391
Poly Trio 8800 Firmware=5.5.3.3441
Poly Trio 8800 Firmware=5.5.3.3517
Poly Trio 8800 Firmware=5.5.4.2255
Poly Trio 8800 Firmware=5.7.1.4095
Poly Trio 8800 Firmware=5.7.1.4133
Poly Trio 8800 Firmware=5.7.1.4145
Poly Trio 8800
Event History
Dec 28, 2021
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-17875?
CVE-2018-17875 is classified as a high-severity remote code execution vulnerability affecting Poly Trio 8800 devices.
2
How do I fix CVE-2018-17875?
To address CVE-2018-17875, update the Poly Trio 8800 firmware to a version that has patched this vulnerability.
3
Who is affected by CVE-2018-17875?
CVE-2018-17875 affects devices running specific vulnerable versions of Poly Trio 8800 firmware, particularly version 5.7.1.4145.
4
What type of vulnerability is CVE-2018-17875?
CVE-2018-17875 is a remote code execution vulnerability, allowing attackers to execute arbitrary commands.
5
Can CVE-2018-17875 be exploited remotely?
Yes, CVE-2018-17875 can be exploited by remote authenticated users to execute commands on the affected devices.