CVE-2022-26481: OS Command Injection
An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26481?
The severity of CVE-2022-26481 is high with a CVSS score of 8.8.
What can occur due to CVE-2022-26481?
Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
What is the affected software of CVE-2022-26481?
The affected software includes Poly Studio X30 Firmware, Poly Studio X70 Firmware, Poly G7500 Firmware, and Poly Studio X50 Firmware.
How can I fix CVE-2022-26481?
Update to Poly Studio version 3.7.0 or later to fix CVE-2022-26481.
Where can I find more information about CVE-2022-26481?
You can find more information about CVE-2022-26481 in the following references: [Sec Consult Advisory](https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/) and [Poly Security Center](https://www.poly.com/us/en/support/security-center).