CVE-2021-41322: High severity Polycom Vvx 400 Firmware vulnerability
Published Oct 4, 2021
·Updated
Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process.
Affected Software
8 affected components
Polycom Vvx 400 Firmware=5.3.1
Polycom Vvx 400
Polycom Vvx 410 Firmware=5.3.1
Polycom Vvx 410
All of the following
Polycom Vvx 400 Firmware=5.3.1
Polycom Vvx 400
All of the following
Polycom Vvx 410 Firmware=5.3.1
Polycom Vvx 410
Event History
Oct 4, 2021
CVE Published
via MITRE·05:52 AM
Data Sourced
via MITRE·05:52 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2021-41322?
CVE-2021-41322 is rated as a high-severity vulnerability due to the potential for unauthorized administrative access.
2
How do I fix CVE-2021-41322?
To fix CVE-2021-41322, update the firmware of Poly VVX 400/410 to a version later than 5.3.1.
3
Who is affected by CVE-2021-41322?
The vulnerability affects users of Poly VVX 400 and 410 phones running firmware version 5.3.1.
4
What type of vulnerability is CVE-2021-41322?
CVE-2021-41322 is a privilege escalation vulnerability that allows low-privileged users to change the admin password.
5
When was CVE-2021-41322 discovered?
CVE-2021-41322 was discovered in 2021, specifically associated with the 5.3.1 firmware release.