CVE-2012-6610
HIGHPolycom HDX Video End Points < 3.0.4 and UC APL < 2.7.1.j - Authenticated OS Command Injection via Ping Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-6610.
Includes Metasploit module exploits/unix/misc/polycom_hdx_auth_bypass.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass vulnerability in Polycom HDX video endpoints (versions 3.0.5 and earlier) by flooding the service with simultaneous connections. It then leverages an OS command injection in the ping command to execute arbitrary commands as root via a reverse shell.
Description
Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.
Exploits (1)
This Metasploit module exploits an authentication bypass vulnerability in Polycom HDX video endpoints (versions 3.0.5 and earlier) by flooding the service with simultaneous connections. It then leverages an OS command injection in the ping command to execute arbitrary commands as root via a reverse shell.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H