CVE-2024-9579
HIGH EPSS 30.9%
Published Nov 5, 20241y ago · Modified Jun 17, 20261w ago
7.5 CVSS 3.1
Published Nov 5, 2024 1y ago
Last Modified Jun 17, 2026 1w ago
Description
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector Adjacent
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
30.9% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-77 Command Injection Injection
Affected Products 16
| Vendor | Product | Version | Range |
|---|---|---|---|
| hp | poly_tc8_firmware | * | <6.3.2 |
| hp | poly_tc8 | * | any |
| hp | poly_tc10_firmware | * | <6.3.2 |
| hp | poly_tc10 | * | any |
| hp | poly_studio_g7500_firmware | * | <4.3.2 |
| hp | poly_studio_g7500 | * | any |
| hp | poly_studio_x30_firmware | * | ≤4.3.2 |
| hp | poly_studio_x30 | * | any |
| hp | poly_studio_x50_firmware | * | <4.3.2 |
| hp | poly_studio_x50 | * | any |
| hp | poly_studio_x70_firmware | * | <4.3.2 |
| hp | poly_studio_x70 | * | any |
| hp | poly_studio_x52_firmware | * | <4.3.2 |
| hp | poly_studio_x52 | * | any |
| hp | poly_studio_g62_firmware | * | <4.3.2 |
| hp | poly_studio_g62 | * | any |
References 1
- support.hp.com https://support.hp.com/us-en/document/ish_11536495-11536533-16/hpsbpy03900
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.