First published: Sun Jul 17 2022(Updated: )
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Poly Studio X30 Firmware | <3.7.0 | |
Poly Studio X30 | ||
Poly Studio X70 Firmware | <3.7.0 | |
Poly Studio X70 | ||
Poly G7500 Firmware | <3.7.0 | |
Poly G7500 | ||
Poly Studio X50 Firmware | <3.7.0 | |
Poly Studio X50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-26481 is high with a CVSS score of 8.8.
Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
The affected software includes Poly Studio X30 Firmware, Poly Studio X70 Firmware, Poly G7500 Firmware, and Poly Studio X50 Firmware.
Update to Poly Studio version 3.7.0 or later to fix CVE-2022-26481.
You can find more information about CVE-2022-26481 in the following references: [Sec Consult Advisory](https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/) and [Poly Security Center](https://www.poly.com/us/en/support/security-center).