VulnerabilityModified
CVE-2018-18566
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
MEDIUM 5.3EPSS 2.75%
Does this matter?
Lower severity and a low EPSS score (2.75%). Track it; it rarely justifies an emergency change on its own.
Description
The SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration information by leveraging use with an on-premise installation with Skype for Business.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 2.75% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- polycom/unified communications software · polycom/vvx 601 firmware · polycom/vvx 500 firmware
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/105746Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2018/Oct/33Exploit, Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-028.txtExploit, Third Party Advisory
- http://www.securityfocus.com/bid/105746Third Party Advisory, VDB Entry
- https://seclists.org/bugtraq/2018/Oct/33Exploit, Mailing List, Third Party Advisory
- https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-028.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.