CVE-2018-18566: Infoleak
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18566?
CVE-2018-18566 is considered a moderate severity vulnerability due to the risk of sensitive phone configuration information being exposed.
How do I fix CVE-2018-18566?
To fix CVE-2018-18566, update the Polycom VVX 500 and 601 devices to a version later than 5.8.0.12848.
What devices are affected by CVE-2018-18566?
CVE-2018-18566 affects Polycom VVX 500 and 601 devices running Unified Communications Software version 5.8.0.12848 and earlier.
What type of attacks can exploit CVE-2018-18566?
CVE-2018-18566 can be exploited by remote attackers to gain access to sensitive configuration information in on-premise installations with Skype for Business.
Is CVE-2018-18566 specific to certain software versions?
Yes, CVE-2018-18566 specifically impacts Polycom Unified Communications Software versions up to and including 5.8.0.12848.