CVE-2022-26481

An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x30:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x70:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:g7500:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x50:-:*:*:*:*:*:*:*

History

21 Jul 2022, 22:46

Type Values Removed Values Added
CWE CWE-78
First Time Poly studio X50 Firmware
Poly g7500 Firmware
Poly g7500
Poly studio X70
Poly studio X30 Firmware
Poly studio X50
Poly
Poly studio X30
Poly studio X70 Firmware
CPE cpe:2.3:h:poly:g7500:-:*:*:*:*:*:*:*
cpe:2.3:o:poly:studio_x70_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x50:-:*:*:*:*:*:*:*
cpe:2.3:o:poly:g7500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x30:-:*:*:*:*:*:*:*
cpe:2.3:o:poly:studio_x50_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:poly:studio_x30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:poly:studio_x70:-:*:*:*:*:*:*:*
References (MISC) https://www.poly.com/us/en/support/security-center - (MISC) https://www.poly.com/us/en/support/security-center - Vendor Advisory
References (MISC) https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/ - (MISC) https://sec-consult.com/vulnerability-lab/advisory/authenticated-command-injection-in-poly-studio/ - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

17 Jul 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-07-17 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-26481

Mitre link : CVE-2022-26481

CVE.ORG link : CVE-2022-26481


JSON object : View

Products Affected

poly

  • g7500
  • studio_x30_firmware
  • studio_x70
  • studio_x50_firmware
  • studio_x30
  • g7500_firmware
  • studio_x50
  • studio_x70_firmware
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')