CVE-2023-4468 MEDIUM

CVE-2023-4468: Poly Trio 8500/Trio 8800/Trio C60 Poly Lens Management Cloud Registration authorization

Vendor Poly
Product Trio 8500
Weakness CWE-862 · Missing authorization
Published December 29, 2023
Last update August 2, 2024

CVSS base score

4.3/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

A vulnerability was found in Poly Trio 8500, Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB-249261 was assigned to this vulnerability.

Key dates

02Disclosure timeline

December 29, 2023 CVE published
August 2, 2024 Record updated