Vulnerability CVE-2023-4465


Published: 2023-12-29

Description:
A vulnerability, which was classified as problematic, was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. Affected is an unknown function of the component Configuration File Import. The manipulation of the argument device.auth.localAdminPassword leads to unverified password change. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249258 is the identifier assigned to this vulnerability.

Type:

CWE-620

(Unverified Password Change)

 References:
https://vuldb.com/?id.249258
https://vuldb.com/?ctiid.249258
https://modzero.com/en/advisories/mz-23-01-poly-voip-devices/
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html

Copyright 2024, cxsecurity.com

 

Back to Top