CVE-2023-24282: XSS
Published Mar 8, 2023
·Updated
An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file.
Affected Software
4 affected components
All of the following
Poly Trio 8800 Firmware=7.2.2.1094
Poly Trio 8800
Poly Trio 8800 Firmware=7.2.2.1094
Poly Trio 8800
Event History
Mar 8, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-24282?
CVE-2023-24282 is an arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 that allows attackers to execute arbitrary code via a crafted ringtone file.
2
What is the severity of CVE-2023-24282?
The severity of CVE-2023-24282 is medium with a CVSS score of 5.4.
3
How does CVE-2023-24282 affect Poly Trio 8800?
CVE-2023-24282 affects Poly Trio 8800 7.2.2.1094 by allowing attackers to execute arbitrary code through a crafted ringtone file.
4
How can I fix CVE-2023-24282?
To fix CVE-2023-24282, update to a version of Poly Trio 8800 firmware that is not affected by this vulnerability.
5
Are there any references for CVE-2023-24282?
Yes, you can find references for CVE-2023-24282 on the Polycom website and the Cryptnetix blog.