Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
None
Privileges Required
None
Attack Vector
Adjacent_network
0

CVE-2024-9579

Disclosure Date: November 05, 2024
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

CVSS V3 Severity and Metrics
Base Score:
7.5 High
Impact Score:
5.9
Exploitability Score:
1.6
Vector:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector (AV):
Adjacent_network
Attack Complexity (AC):
High
Privileges Required (PR):
None
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High

General Information

Vendors

  • hp

Products

  • poly studio g62 firmware,
  • poly studio g7500 firmware,
  • poly studio x30 firmware,
  • poly studio x50 firmware,
  • poly studio x52 firmware,
  • poly studio x70 firmware,
  • poly tc10 firmware,
  • poly tc8 firmware

Additional Info

Technical Analysis