8.8
CVSSv3

CVE-2022-26481

Published: 17/07/2022 Updated: 21/07/2022
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

An issue exists in Poly Studio prior to 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

poly studio_x30_firmware

poly studio_x70_firmware

poly g7500_firmware

poly studio_x50_firmware

Exploits

Poly Studio X30, Studio X50, Studio X70, and G7500 versions 340-292042, 350-344025, and 360 suffers from an authenticated command injection vulnerability ...