CVE-2025-22918

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.
Configurations

No configuration.

History

18 Mar 2025, 19:15

Type Values Removed Values Added
CWE CWE-200
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

18 Feb 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : unknown
CWE CWE-276

04 Feb 2025, 15:15

Type Values Removed Values Added
CWE CWE-276
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Polycom RealPresence Group 500 &lt;=20 tiene permisos inseguros debido a la carga automática de cookies. Esto permite el uso de funciones de administrador, lo que da como resultado la filtración de información confidencial del usuario.

03 Feb 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-03 21:15

Updated : 2025-03-18 19:15


NVD link : CVE-2025-22918

Mitre link : CVE-2025-22918

CVE.ORG link : CVE-2025-22918


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor