CVE-2019-11355: OS Command Injection
An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user is the factor value of a shell script on the equipment. By entering a special character (such as a single quote) in a CN or other CSR field, one can insert a command into a factor value. A system command can be executed as root.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-11355?
CVE-2019-11355 has a medium severity rating due to potential unauthorized access to sensitive features.
How do I fix CVE-2019-11355?
To fix CVE-2019-11355, upgrade to Poly HDX system software version 3.1.14 or later.
What are the implications of CVE-2019-11355?
CVE-2019-11355 could allow an attacker to execute arbitrary shell commands by exploiting user input vulnerabilities.
Which Polycom HDX versions are affected by CVE-2019-11355?
CVE-2019-11355 affects Polycom HDX system software versions up to and including 3.1.13.
Is there a workaround for CVE-2019-11355?
Currently, the recommended action for CVE-2019-11355 is to apply the software update rather than relying on a specific workaround.