9.8
CVSSv3

CVE-2022-26479

Published: 17/07/2022 Updated: 22/07/2022
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in Poly EagleEye Director II prior to 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

poly eagleeye_director_ii_firmware

Exploits

Poly EagleEye Director II version 2211 suffers from multiple authenticated remote command injection vulnerabilities as well as an authentication bypass vulnerability ...