CVE-2022-26479: Critical severity poly eagleeye director ii firmware vulnerability
Published Jul 17, 2022
·Updated
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.
Affected Software
2 affected components
Poly Eagleeye Director Ii Firmware<2.2.2.1
Poly EagleEye Director II
Event History
Jul 17, 2022
CVE Published
via MITRE·10:01 PM
Data Sourced
via MITRE·10:01 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-26479.
2
What is the severity rating for CVE-2022-26479?
CVE-2022-26479 has a severity rating of 9.8 (Critical).
3
What is the affected software for CVE-2022-26479?
The affected software for CVE-2022-26479 is Poly EagleEye Director II firmware versions up to 2.2.2.1.
4
How can an attacker exploit CVE-2022-26479?
An attacker can exploit CVE-2022-26479 by creating a certain file via an rsync backdoor, which will cause all API calls to execute as admin without authentication.
5
Are there any known fixes or patches for CVE-2022-26479?
Yes, it is recommended to update to Poly EagleEye Director II firmware version 2.2.2.1 or later to mitigate CVE-2022-26479.