A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249259.
References
Link | Resource |
---|---|
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html | Not Applicable |
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices | |
https://modzero.com/en/advisories/mz-23-01-poly-voip/ | |
https://vuldb.com/?ctiid.249259 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.249259 | Third Party Advisory VDB Entry |
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html | Not Applicable |
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices | |
https://modzero.com/en/advisories/mz-23-01-poly-voip/ | |
https://vuldb.com/?ctiid.249259 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.249259 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.3
v3 : 2.7 |
References | () https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html - Not Applicable | |
References | () https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices - | |
References | () https://modzero.com/en/advisories/mz-23-01-poly-voip/ - | |
References | () https://vuldb.com/?ctiid.249259 - Permissions Required, Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?id.249259 - Third Party Advisory, VDB Entry |
09 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
05 Jan 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
First Time |
Poly trio 8800 Firmware
Poly ccx 600 Poly trio C60 Poly trio 8800 Poly trio C60 Firmware Poly Poly ccx 400 Firmware Poly ccx 600 Firmware Poly ccx 400 |
|
CPE | cpe:2.3:o:poly:trio_c60_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:poly:trio_8800:-:*:*:*:*:*:*:* cpe:2.3:o:poly:ccx_400_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:poly:ccx_600_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:poly:ccx_400:-:*:*:*:*:*:*:* cpe:2.3:h:poly:ccx_600:-:*:*:*:*:*:*:* cpe:2.3:o:poly:trio_8800_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:poly:trio_c60:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
References | () https://vuldb.com/?id.249259 - Third Party Advisory, VDB Entry | |
References | () https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html - Not Applicable | |
References | () https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/ - Broken Link | |
References | () https://vuldb.com/?ctiid.249259 - Permissions Required, Third Party Advisory, VDB Entry |
29 Dec 2023, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-29 10:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4466
Mitre link : CVE-2023-4466
CVE.ORG link : CVE-2023-4466
JSON object : View
Products Affected
poly
- ccx_600_firmware
- trio_8800
- trio_8800_firmware
- ccx_400
- ccx_600
- trio_c60_firmware
- ccx_400_firmware
- trio_c60
CWE
CWE-693
Protection Mechanism Failure