CVE-2019-10689: Medium severity polycom better together over ethernet connector vulnerability
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10689?
CVE-2019-10689 is rated as a medium severity vulnerability.
How do I fix CVE-2019-10689?
To fix CVE-2019-10689, update to the latest versions of the Polycom Unified Communications Software and Better Together over Ethernet Connector.
What information is leaked due to CVE-2019-10689?
CVE-2019-10689 can lead to leakage of sensitive information due to insufficient authentication between the BToE application and its component.
Which products are affected by CVE-2019-10689?
CVE-2019-10689 affects VVX products using UCS software version 5.9.2 and earlier along with BToE application version 3.9.1 and earlier.
Is CVE-2019-10689 a local or remote vulnerability?
CVE-2019-10689 can be exploited remotely due to the insufficient authentication mechanism.