CVE-2019-10689

MEDIUM

Polycom VVX UCS < 5.9.2 and BToE < 3.9.1 - Insufficient Authentication and Information Leakage

Title source: llm
STIX 2.1

Description

VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/108799

Scores

CVSS v3 6.5
EPSS 0.0072
EPSS Percentile 49.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-287
Status published
Products (2)
polycom/better_together_over_ethernet_connector < 3.9.1
polycom/unified_communications_software < 5.9.2
Published Jun 24, 2019
Tracked Since Feb 18, 2026