CVE-2019-12948: High severity polycom unified communications software vulnerability
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-12948?
The severity of CVE-2019-12948 is considered critical due to the potential for a denial of service or remote code execution.
How do I fix CVE-2019-12948?
To fix CVE-2019-12948, you must update the Polycom Unified Communications Software to a version higher than 5.9.3.2857 or 5.8.5.1256.
What products are affected by CVE-2019-12948?
CVE-2019-12948 affects Polycom VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running vulnerable versions of Polycom UC Software.
Can CVE-2019-12948 be exploited remotely?
Yes, CVE-2019-12948 can be exploited remotely by an authenticated attacker with admin privileges.
What are the potential impacts of CVE-2019-12948?
The potential impacts of CVE-2019-12948 include causing a denial of service condition and executing arbitrary code on the affected devices.