CVE-2019-12948: High severity polycom unified communications software vulnerability

Published Jul 29, 2019
·
Updated

A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.

Affected Software

57 affected components
Polycom Unified Communications Software<5.8.5.1256
Polycom Unified Communications Software>=5.9.3<5.9.3.2857
Polycom Unified Communications Software>=6.0.0<6.0.0.4839
Polycom C12
Polycom C16
Polycom C8
Polycom Vvx150
Polycom Vvx201
Polycom Vvx250
Polycom Vvx301
Polycom Vvx311
Polycom Vvx350
Polycom Vvx401
Polycom Vvx411
Polycom Vvx450
Polycom Vvx501
Polycom Vvx601
Polycom United Communications Software<5.9.0
Polycom Trio 8500
Polycom Trio 8800
Polycom United Communications Software<4.0.14.1580
Polycom Soundpoint Ip 300
Polycom SoundPoint IP 301
Polycom Soundpoint Ip 320
Polycom Soundpoint Ip 321
Polycom Soundpoint Ip 330
Polycom Soundpoint Ip 331
Polycom Soundpoint Ip 335
Polycom Soundpoint Ip 430
Polycom Soundpoint Ip 450
Polycom Soundpoint Ip 500
Polycom Soundpoint Ip 501
Polycom Soundpoint Ip 550
Polycom Soundpoint Ip 560
Polycom Soundpoint Ip 600
Polycom SoundPoint IP 601
Polycom Soundpoint Ip 650
Polycom Soundpoint Ip 670
Polycom Soundpoint Pro Se-220
Polycom Soundpoint Pro Se-225
Polycom Soundstation Duo
Polycom Soundstation Ip 4000
Polycom Soundstation Ip 5000
Polycom Soundstation Ip 6000
Polycom Soundstation Ip 7000
Polycom Soundstation Ip 7000 Video Integration
Polycom Soundstation Vtx 1000
Polycom Soundstation2
Polycom Soundstation2 Avaya 2490
Polycom Soundstation2 Direct Connect For Nortel
Polycom Soundstation2w
Polycom Vvx300
Polycom Vvx310
Polycom Vvx400
Polycom Vvx410
Polycom Vvx500
Polycom Vvx600

Event History

Jul 29, 2019
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2019-12948?

The severity of CVE-2019-12948 is considered critical due to the potential for a denial of service or remote code execution.

2

How do I fix CVE-2019-12948?

To fix CVE-2019-12948, you must update the Polycom Unified Communications Software to a version higher than 5.9.3.2857 or 5.8.5.1256.

3

What products are affected by CVE-2019-12948?

CVE-2019-12948 affects Polycom VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running vulnerable versions of Polycom UC Software.

4

Can CVE-2019-12948 be exploited remotely?

Yes, CVE-2019-12948 can be exploited remotely by an authenticated attacker with admin privileges.

5

What are the potential impacts of CVE-2019-12948?

The potential impacts of CVE-2019-12948 include causing a denial of service condition and executing arbitrary code on the affected devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203