SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-18566

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.

MEDIUM 5.3EPSS 2.75%

Does this matter?

Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.

Description

The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
2.75% probability · 85th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
polycom/unified communications software · polycom/vvx 601 firmware · polycom/vvx 500 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.