First published: Tue Nov 05 2024(Updated: )
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
Credit: hp-security-alert@hp.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Hp Poly Tc8 Firmware | <6.3.2 | |
HP Poly TC8 | ||
All of | ||
HP Poly TC10 Firmware | <6.3.2 | |
HP Poly TC10 | ||
All of | ||
HP Poly Studio G7500 | <4.3.2 | |
HP Poly Studio G7500 | ||
All of | ||
Poly Studio X30 Firmware | <=4.3.2 | |
Poly Studio X30 | ||
All of | ||
Poly Studio X50 Firmware | <4.3.2 | |
Poly Studio X50 | ||
All of | ||
Poly Studio X70 | <4.3.2 | |
HP Poly Studio X70 Firmware | ||
All of | ||
HP Poly Studio X52 Firmware | <4.3.2 | |
HP Poly Studio X52 Firmware | ||
All of | ||
Hp Poly Studio G62 Firmware | <4.3.2 | |
Hp Poly Studio G62 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9579 is classified as a medium severity vulnerability due to its requirement for layered attack exploitation.
To fix CVE-2024-9579, update the vulnerable Poly video conferencing devices to the latest firmware that addresses the flaw.
CVE-2024-9579 affects specific firmware versions of Poly TC8, TC10, Studio G7500, Studio X30, Studio X50, Studio X70, Studio X52, and Studio G62 devices.
CVE-2024-9579 cannot be exploited by itself; it requires a layered attack approach to be successful.
CVE-2024-9579 is a firmware flaw that fails to properly sanitize user input, potentially allowing exploitation through additional attack vectors.