CVE-2023-4466

Published: Dic 29, 2023 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2023-54321 Aliases: GSD-2023-4466
ExploitDB:
Other exploit source:
Google Dorks:
LOW 2,7
Attack Vector: network
Attack Complexity: low
Privileges Required: high
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: low
Availability: none
LOW 3,3
Access Vector: network
Access Complexity: low
Authentication: multiple
Confidentiality: none
Integrity: partial
Availability: none

Description

AI Translation Available

A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential roll-back attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249259.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0010
Percentile
0,3th
Updated

EPSS Score Trend (Last 90 Days)

693

Protection Mechanism Failure

Draft
Common Consequences
Security Scopes Affected:
Access Control
Potential Impacts:
Bypass Protection Mechanism
Applicable Platforms
Technologies: Not Technology-Specific, ICS/OT
View CWE Details
Operating System

Ccx 600 Firmware by Poly

cpe:2.3:o:poly:ccx_600_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Trio C60 Firmware by Poly

cpe:2.3:o:poly:trio_c60_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Trio 8800 Firmware by Poly

cpe:2.3:o:poly:trio_8800_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ccx 400 Firmware by Poly

cpe:2.3:o:poly:ccx_400_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices
https://modzero.com/en/advisories/mz-23-01-poly-voip/
https://vuldb.com/?ctiid.249259
Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?ctiid.249259
https://vuldb.com/?id.249259
Third Party Advisory VDB Entry
https://vuldb.com/?id.249259
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices
https://modzero.com/en/advisories/mz-23-01-poly-voip/
https://vuldb.com/?ctiid.249259
Permissions Required Third Party Advisory VDB Entry
https://vuldb.com/?ctiid.249259
https://vuldb.com/?id.249259
Third Party Advisory VDB Entry
https://vuldb.com/?id.249259