A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249259.
References
Link | Resource |
---|---|
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html | Not Applicable |
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices | |
https://modzero.com/en/advisories/mz-23-01-poly-voip/ | |
https://vuldb.com/?ctiid.249259 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.249259 | Third Party Advisory VDB Entry |
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html | Not Applicable |
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices | |
https://modzero.com/en/advisories/mz-23-01-poly-voip/ | |
https://vuldb.com/?ctiid.249259 | Permissions Required Third Party Advisory VDB Entry |
https://vuldb.com/?id.249259 | Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 08:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.3
v3 : 2.7 |
References | () https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html - Not Applicable | |
References | () https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices - | |
References | () https://modzero.com/en/advisories/mz-23-01-poly-voip/ - | |
References | () https://vuldb.com/?ctiid.249259 - Permissions Required, Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?id.249259 - Third Party Advisory, VDB Entry |
09 Jan 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
05 Jan 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:poly:trio_8800_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:poly:ccx_400:-:*:*:*:*:*:*:* cpe:2.3:h:poly:trio_c60:-:*:*:*:*:*:*:* cpe:2.3:o:poly:ccx_400_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:poly:ccx_600_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:poly:trio_c60_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:poly:ccx_600:-:*:*:*:*:*:*:* cpe:2.3:h:poly:trio_8800:-:*:*:*:*:*:*:* |
|
First Time |
Poly ccx 400 Firmware
Poly trio C60 Firmware Poly Poly trio 8800 Firmware Poly ccx 600 Poly trio 8800 Poly trio C60 Poly ccx 400 Poly ccx 600 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
References | () https://vuldb.com/?ctiid.249259 - Permissions Required, Third Party Advisory, VDB Entry | |
References | () https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/ - Broken Link | |
References | () https://vuldb.com/?id.249259 - Third Party Advisory, VDB Entry | |
References | () https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html - Not Applicable |
29 Dec 2023, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-29 10:15
Updated : 2024-11-21 08:35
NVD link : CVE-2023-4466
Mitre link : CVE-2023-4466
CVE.ORG link : CVE-2023-4466
JSON object : View
Products Affected
poly
- ccx_600
- trio_8800
- trio_c60_firmware
- ccx_600_firmware
- trio_8800_firmware
- trio_c60
- ccx_400
- ccx_400_firmware
CWE
CWE-693
Protection Mechanism Failure