VVX products using UCS software version 5.9.2 and earlier with Better Together over Ethernet Connector (BToE) application version 3.9.1 and earlier provides insufficient authentication between the BToE application and the BToE component, resulting in leakage of sensitive information.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108799 | Third Party Advisory VDB Entry |
https://support.polycom.com/content/dam/polycom-support/global/documentation/insufficient-authentication-leakage-vvx-products.pdf | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2019-06-24T21:10:20
Updated: 2019-06-24T21:11:17
Reserved: 2019-04-01T00:00:00
Link: CVE-2019-10689
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-06-24T22:15:08.960
Modified: 2019-06-27T17:26:21.897
Link: CVE-2019-10689
JSON object: View
Redhat Information
No data.
CWE