CVE-2022-26481

An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x70:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:g7500:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x50:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-07-17 23:15

Updated : 2024-02-28 19:29


NVD link : CVE-2022-26481

Mitre link : CVE-2022-26481

CVE.ORG link : CVE-2022-26481


JSON object : View

Products Affected

poly

  • studio_x70_firmware
  • studio_x50_firmware
  • studio_x30
  • studio_x50
  • g7500_firmware
  • studio_x70
  • studio_x30_firmware
  • g7500
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')