CVE-2025-22918

HIGH

Polycom RealPresence Group 500 <=20 - Info Disclosure

Title source: llm
STIX 2.1

Description

Polycom RealPresence Group 500 <=20 has Insecure Permissions due to automatically loaded cookies. This allows for the use of administrator functions, resulting in the leakage of sensitive user information.

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 26.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Published Feb 03, 2025
Tracked Since Feb 18, 2026