Description
A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.
References (7)
Core 7
Core References
Third Party Advisory
https://modzero.com/en/blog/multiple-vulnerabilities-in-poly-products/
Third Party Advisory vdb-entry
https://vuldb.com/?id.249261
Permissions Required, Third Party Advisory signature
permissions-required
https://vuldb.com/?ctiid.249261
Various Sources related
https://modzero.com/en/advisories/mz-23-01-poly-voip/
Various Sources related
https://support.hp.com/us-en/document/ish_9929447-9929472-16/hpsbpy03902
Various Sources exploit
https://github.com/modzero/MZ-23-01-Poly-VoIP-Devices
Not Applicable related
https://fahrplan.events.ccc.de/congress/2023/fahrplan/events/11919.html
Scores
CVSS v3
4.3
EPSS
0.0006
EPSS Percentile
19.6%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-862
Status
published
Products (3)
poly/lens
poly/trio_8800_firmware
poly/trio_c60
Published
Dec 29, 2023
Tracked Since
Feb 18, 2026