CVE-2022-26481

An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x70:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:g7500:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x50:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:54

Type Values Removed Values Added
References () https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/ - Exploit, Third Party Advisory () https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/ - Exploit, Third Party Advisory
References () https://www.poly.com/us/en/support/security-center - Vendor Advisory () https://www.poly.com/us/en/support/security-center - Vendor Advisory

Information

Published : 2022-07-17 23:15

Updated : 2024-11-21 06:54


NVD link : CVE-2022-26481

Mitre link : CVE-2022-26481

CVE.ORG link : CVE-2022-26481


JSON object : View

Products Affected

poly

  • g7500_firmware
  • g7500
  • studio_x70_firmware
  • studio_x30
  • studio_x70
  • studio_x30_firmware
  • studio_x50_firmware
  • studio_x50
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')