VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108799 | Third Party Advisory VDB Entry |
https://support.polycom.com/content/dam/polycom-support/global/documentation/insufficient-authentication-leakage-vvx-products.pdf | Vendor Advisory |
http://www.securityfocus.com/bid/108799 | Third Party Advisory VDB Entry |
https://support.polycom.com/content/dam/polycom-support/global/documentation/insufficient-authentication-leakage-vvx-products.pdf | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/108799 - Third Party Advisory, VDB Entry | |
References | () https://support.polycom.com/content/dam/polycom-support/global/documentation/insufficient-authentication-leakage-vvx-products.pdf - Vendor Advisory |
Information
Published : 2019-06-24 22:15
Updated : 2024-11-21 04:19
NVD link : CVE-2019-10689
Mitre link : CVE-2019-10689
CVE.ORG link : CVE-2019-10689
JSON object : View
Products Affected
polycom
- better_together_over_ethernet_connector
- unified_communications_software
CWE
CWE-287
Improper Authentication