CVE-2018-18568: Medium severity polycom unified communications software vulnerability
Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18568?
CVE-2018-18568 is considered a high severity vulnerability due to its potential for man-in-the-middle attacks.
How do I fix CVE-2018-18568?
To fix CVE-2018-18568, update the Polycom VVX 500 and 601 devices to a version later than 5.8.0.12848 that properly validates X.509 certificates.
What devices are affected by CVE-2018-18568?
CVE-2018-18568 affects Polycom VVX 500 and VVX 601 devices running Unified Communications Software version 5.8.0.12848 and earlier.
What kind of information can be compromised due to CVE-2018-18568?
CVE-2018-18568 allows attackers to obtain sensitive credential information from affected Polycom devices.
Can I use Polycom VVX 500 or 601 devices without risk of CVE-2018-18568?
Yes, as long as the software version on the Polycom VVX 500 or 601 devices is updated beyond version 5.8.0.12848, the risk is mitigated.