Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.3)1.7%—Polycom Unified Communications SoftwarePolycom United Communications Software29/7/201917/6/2026
A vulnerability in the web-based management interface of VVX, Trio, SoundStructure, SoundPoint, and SoundStation phones running Polycom UC Software, if exploited, could allow an authenticated, remote attacker with admin privileges to cause a denial of service (DoS) condition or execute arbitrary code.
ModificadaMedia (6.5)0.72%—Polycom Better Together Over Ethernet ConnectorPolycom Unified Communications Software24/6/201917/6/2026
VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
ModificadaMedia (6.8)0.32%—Polycom Unified Communications SoftwarePolycom Better Together Over Ethernet Connector23/4/201917/6/2026
VVX products with software versions including and prior to, UCS 5.9.2 with Better Together over Ethernet Connector (BToE) application 3.9.1, use hard-coded credentials to establish connections between the host application and the device.
ModificadaMedia (5.9)0.73%—Polycom Unified Communications SoftwarePolycom VVX 601 FirmwarePolycom VVX 500 Firmware24/10/201817/6/2026
Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.
ModificadaMedia (5.3)2.8%—Polycom Unified Communications SoftwarePolycom VVX 601 FirmwarePolycom VVX 500 Firmware24/10/201817/6/2026
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
ModificadaAlta (8.8)1.6%—Polycom Unified Communications Software25/8/201717/6/2026
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application. This vulnerability could allow an authenticated remote attacker to read a segment of the phone's memory which could…