CVE-2019-10688: Medium severity polycom unified communications software vulnerability
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10688?
CVE-2019-10688 is considered a high severity vulnerability due to the use of hard-coded credentials.
How do I fix CVE-2019-10688?
To fix CVE-2019-10688, upgrade to the latest version of Polycom Unified Communications Software and BToE application that addresses this vulnerability.
What products are affected by CVE-2019-10688?
CVE-2019-10688 affects Polycom VVX products running UCS versions inclusive of 5.9.2 and Better Together over Ethernet Connector versions inclusive of 3.9.1.
What are the implications of CVE-2019-10688?
The implications of CVE-2019-10688 include potential unauthorized access to Polycom devices due to the use of hard-coded credentials.
Is there a workaround for CVE-2019-10688?
There are no known workarounds for CVE-2019-10688, so upgrading to a fixed version is essential for mitigation.