CVE-2021-37145: Command Injection
UNSUPPORTED WHEN ASSIGNED A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37145?
CVE-2021-37145 is classified as a critical vulnerability due to its potential for privilege escalation and remote code execution.
What devices are affected by CVE-2021-37145?
CVE-2021-37145 affects the Poly CX5500 and CX5100 devices running firmware version 1.3.5.
How do I fix CVE-2021-37145?
There is no fix available for CVE-2021-37145 as it pertains to unsupported products.
Can CVE-2021-37145 be exploited remotely?
Yes, CVE-2021-37145 can be exploited remotely due to its command-injection nature in an authenticated Telnet connection.
Is CVE-2021-37145 a zero-day vulnerability?
CVE-2021-37145 is not classified as a zero-day vulnerability since it affects unsupported versions of software.