Description
A vulnerability was discovered in the firmware builds up to 8.2.1.0820 in certain Poly devices. The firmware flaw does not properly prevent path traversal and could lead to information disclosure.
Scores
CVSS v4
5.8
EPSS
0.0005
EPSS Percentile
16.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-35
Status
published
Products (1)
HP, Inc./Certain Poly Devices
See HP security bulletin reference for affected versions
Published
Feb 05, 2025
Tracked Since
Feb 18, 2026